A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1943 | third party advisory |
https://community.automationdirect.com/s/internal-database-security-advisory/a4GPE0000003ycL2AQ/sa00039 | vendor advisory |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1943 | third party advisory |