CVE-2024-1015
קריטית 9.8
תיאור (מקור, אנגלית)
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-94
מוצרים מושפעים
se-elektronic: e-ddc3.3 firmware; se-elektronic: e-ddc3.3
קישורים
- https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.html Third Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilitie… Third Party Advisory
- https://www.se-elektronic.com/.well-known/csaf/advisories/2026/se-sa-2026_001.…
- https://www.se-elektronic.com/psirt-cybersecurity/
- https://www.hackplayers.com/2024/01/cve-2024-1014-and-cve-2024-1015.html Third Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilitie… Third Party Advisory