CVE-2024-51330

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and transmission components, Ultimaker 3D Printers.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ultimaker:ultimaker_cura:*:*:*:*:*:*:*:*

History

29 Jun 2026, 17:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 5.1
References () https://gist.github.com/HalaAli198/ff06d7a94c06cdfb821dec4d6303e01b - () https://gist.github.com/HalaAli198/ff06d7a94c06cdfb821dec4d6303e01b - Third Party Advisory
CPE cpe:2.3:a:ultimaker:ultimaker_cura:*:*:*:*:*:*:*:*
First Time Ultimaker ultimaker Cura
Ultimaker

27 Nov 2024, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.4
CWE CWE-94

18 Nov 2024, 17:11

Type Values Removed Values Added
Summary
  • (es) Un problema en UltiMaker Cura v.4.41 y 5.8.1 y anteriores permite a un atacante local ejecutar código arbitrario a través del mecanismo de comunicación entre procesos (IPC) entre la aplicación Cura y los procesos de CuraEngine, la pila de red del host local, las configuraciones de impresión y los componentes de procesamiento y transmisión de código G, impresoras 3D Ultimaker.

15 Nov 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 19:15

Updated : 2026-06-29 17:47


NVD link : CVE-2024-51330

Mitre link : CVE-2024-51330

CVE.ORG link : CVE-2024-51330


JSON object : View

Products Affected

ultimaker

  • ultimaker_cura
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')