CVE-2024-50960

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:extron:sme_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:sme_211:-:*:*:*:*:*:*:*

History

25 Apr 2025, 18:35

Type Values Removed Values Added
First Time Extron sme 211
Extron sme 211 Firmware
CPE cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:sme_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:sme_211:-:*:*:*:*:*:*:*

22 Apr 2025, 18:00

Type Values Removed Values Added
First Time Extron smp 352 Firmware
Extron smp 211 Firmware
Extron smp 352
Extron smp 111 Firmware
Extron smp 351 Firmware
Extron smp 111
Extron
Extron smp 351
Extron smp 211
CPE cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
References () https://github.com/layer8secure/extron-smp-inject/ - () https://github.com/layer8secure/extron-smp-inject/ - Exploit, Third Party Advisory
References () https://ryanmroth.com/articles/exploiting-extron-smp-command-injection - () https://ryanmroth.com/articles/exploiting-extron-smp-command-injection - Exploit, Third Party Advisory
References () https://www.extron.com/article/smp - () https://www.extron.com/article/smp - Product

18 Apr 2025, 14:15

Type Values Removed Values Added
Summary (en) A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, and SMP 352 <= 2.16 allows a remote authenticated attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system. (en) A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

16 Apr 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección de comandos en Nmap diagnostic tool in the admin web console of Extron SMP 111 &lt;=3.01, SMP 351 &lt;=2.16, and SMP 352 &lt;= 2.16 permite que un atacante remoto autenticado con privilegios administrativos ejecute comandos arbitrarios como root en el sistema operativo subyacente.
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

15 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 18:15

Updated : 2025-04-25 18:35


NVD link : CVE-2024-50960

Mitre link : CVE-2024-50960

CVE.ORG link : CVE-2024-50960


JSON object : View

Products Affected

extron

  • smp_352
  • sme_211_firmware
  • smp_111_firmware
  • smp_352_firmware
  • sme_211
  • smp_111
  • smp_351
  • smp_351_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')