CVE-2024-10498
Last modified
CVE-2024-10498 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow an unauthorized attacker to modify configuration values outside of the normal range when the attacker sends specific Modbus write packets to the device which could result in invalid data or loss of web interface functionality.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow an unauthorized attacker to modify configuration values outside of the normal range when the attacker sends specific Modbus write packets to the device which could result in invalid data or loss of web interface functionality.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-10498?
How severe is CVE-2024-10498?
How do I fix CVE-2024-10498?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10492A vulnerability was found in Keycloak. A user with high priv…2.7
- CVE-2024-10493The Element Pack Elementor Addons (Header Footer, Template L…5.4
- CVE-2024-10494An out of bounds read due to improper input validation in He…7.8
- CVE-2024-10495An out of bounds read due to improper input validation when …7.8
- CVE-2024-10496An out of bounds read due to improper input validation in Bu…7.8
- CVE-2024-10497CWE-639: Authorization Bypass Through User-Controlled Key vu…8.8
- CVE-2024-10499The AI Engine WordPress plugin before 2.6.5 does not sanitiz…7.2
- CVE-2024-1050The Import and export users and customers plugin for WordPre…4.3
- CVE-2024-10500A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-10501A vulnerability, which was classified as critical, was found…8.8
- CVE-2024-10502A vulnerability has been found in ESAFENET CDG 5 and classif…8.8
- CVE-2024-10503A vulnerability was found in Klokan MapTiler tileserver-gl 2…6.1
Are you affected by CVE-2024-10498?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
