An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and transmission components, Ultimaker 3D Printers.
References
| Link | Resource |
|---|---|
| https://gist.github.com/HalaAli198/ff06d7a94c06cdfb821dec4d6303e01b | Third Party Advisory |
Configurations
History
29 Jun 2026, 17:47
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.1 |
| References | () https://gist.github.com/HalaAli198/ff06d7a94c06cdfb821dec4d6303e01b - Third Party Advisory | |
| CPE | cpe:2.3:a:ultimaker:ultimaker_cura:*:*:*:*:*:*:*:* | |
| First Time |
Ultimaker ultimaker Cura
Ultimaker |
27 Nov 2024, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.4 |
| CWE | CWE-94 |
18 Nov 2024, 17:11
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
15 Nov 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-11-15 19:15
Updated : 2026-06-29 17:47
NVD link : CVE-2024-51330
Mitre link : CVE-2024-51330
CVE.ORG link : CVE-2024-51330
JSON object : View
Products Affected
ultimaker
- ultimaker_cura
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
