Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "07" allows a local attacker to execute arbitrary code by saving a malicious file to a specific folder. As a result, the attacker may disclose, tamper with, destroy or delete information in the product, or cause a denial-of-service (DoS) condition on the product.
References
Configurations
No configuration.
History
21 Nov 2024, 09:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/vu/JVNVU91215350/index.html - | |
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-191-02 - | |
References | () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-003_en.pdf - |
23 Jul 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
05 Jul 2024, 12:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
04 Jul 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-04 09:15
Updated : 2024-11-21 09:30
NVD link : CVE-2024-3904
Mitre link : CVE-2024-3904
CVE.ORG link : CVE-2024-3904
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions