A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability.
                
            References
                    | Link | Resource | 
|---|---|
| https://community.automationdirect.com/s/internal-database-security-advisory/a4GPE0000003y1F2AQ/sa00025 | Vendor Advisory | 
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-1936 | Exploit Third Party Advisory | 
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1936 | Exploit Third Party Advisory | 
| https://community.automationdirect.com/s/internal-database-security-advisory/a4GPE0000003y1F2AQ/sa00025 | Vendor Advisory | 
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-1936 | Exploit Third Party Advisory | 
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1936 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
Configuration 4 (hide)
| AND | 
            
            
 
  | 
    
Configuration 5 (hide)
| AND | 
            
            
 
  | 
    
Configuration 6 (hide)
| AND | 
            
            
 
  | 
    
History
                    12 Feb 2025, 17:30
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:automationdirect:p3-530_firmware:1.2.10.9:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p1-550_firmware:1.2.10.10:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p1-540_firmware:4.1.1.10:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p2-550_firmware:1.2.10.10:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p2-550_firmware:4.1.1.10:*:*:*:*:*:*:* cpe:2.3:h:automationdirect:p1-540:-:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p1-550_firmware:4.1.1.10:*:*:*:*:*:*:* cpe:2.3:h:automationdirect:p3-530:-:*:*:*:*:*:*:* cpe:2.3:h:automationdirect:p3-550e:-:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p3-550_firmware:4.1.1.10:*:*:*:*:*:*:* cpe:2.3:h:automationdirect:p3-550:-:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p3-550_firmware:1.2.10.9:*:*:*:*:*:*:* cpe:2.3:h:automationdirect:p2-550:-:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p3-530_firmware:4.1.1.10:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p1-540_firmware:1.2.10.10:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p3-550e_firmware:4.1.1.10:*:*:*:*:*:*:* cpe:2.3:o:automationdirect:p3-550e_firmware:1.2.10.9:*:*:*:*:*:*:* cpe:2.3:h:automationdirect:p1-550:-:*:*:*:*:*:*:*  | 
|
| First Time | 
        
        Automationdirect p3-550 Firmware
         Automationdirect p1-550 Firmware Automationdirect p2-550 Firmware Automationdirect p1-540 Automationdirect p3-530 Firmware Automationdirect p1-540 Firmware Automationdirect p2-550 Automationdirect Automationdirect p1-550 Automationdirect p3-550e Automationdirect p3-530 Automationdirect p3-550e Firmware Automationdirect p3-550  | 
|
| References | () https://community.automationdirect.com/s/internal-database-security-advisory/a4GPE0000003y1F2AQ/sa00025 - Vendor Advisory | |
| References | () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1936 - Exploit, Third Party Advisory | |
| References | () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1936 - Exploit, Third Party Advisory | |
| CWE | CWE-787 | 
21 Nov 2024, 08:59
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://community.automationdirect.com/s/internal-database-security-advisory/a4GPE0000003y1F2AQ/sa00025 - | |
| References | () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1936 - | |
| References | () https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1936 - | 
10 Jun 2024, 17:16
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
29 May 2024, 13:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
|
| References | 
        
        
  | 
28 May 2024, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-05-28 16:15
Updated : 2025-02-12 17:30
NVD link : CVE-2024-24851
Mitre link : CVE-2024-24851
CVE.ORG link : CVE-2024-24851
JSON object : View
Products Affected
                automationdirect
- p3-550
 - p1-550_firmware
 - p2-550
 - p3-530_firmware
 - p2-550_firmware
 - p1-550
 - p1-540_firmware
 - p3-550_firmware
 - p1-540
 - p3-530
 - p3-550e_firmware
 - p3-550e
 
