Vulnerability Description
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Se-Elektronic | E-Ddc3.3 Firmware | 03.07.03 |
| Se-Elektronic | E-Ddc3.3 | - |
Related Weaknesses (CWE)
References
- https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.htmlThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-Third Party Advisory
- https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.htmlThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-Third Party Advisory
FAQ
What is CVE-2024-1015?
CVE-2024-1015 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the...
How severe is CVE-2024-1015?
CVE-2024-1015 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-1015?
Check the references section above for vendor advisories and patch information. Affected products include: Se-Elektronic E-Ddc3.3 Firmware, Se-Elektronic E-Ddc3.3.