VDB

CVE-2024-12430

CVE-2024-12430 PUBLISHED CVSS 7 HIGH

After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject arbitrary commands into a specifically crafted file, which then will be executed by root user

EPSS 0.10% · 27.2th percentile

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.10%
27.2th percentile

Affected Products

VendorProductVersions
ABBAC500 V3 products (PM5xxx) < 3.8.0

Timeline

  • Jan 7, 2025 CVE Published
  • Jan 7, 2025 PoC Published
  • Jan 7, 2025 PoC Published
  • Jan 7, 2025 PoC Published
  • Jan 7, 2025 PoC Published
  • Jan 8, 2025 EPSS Score
  • Jan 16, 2025 PoC Published
  • Jan 20, 2025 Coalition ESS Score
  • Jan 24, 2025 EPSS Score
  • Feb 9, 2025 EPSS Score
  • Feb 24, 2025 EPSS Score
  • Mar 12, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›