CVE-2024-11013

CWE-77Command Injection3 documents3 sources
Severity
7.2HIGH
EPSS
0.1%
top 82.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29

Description

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

CVEListV5nec_corporation/univerge_ixfor Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14, from Ver9.2 to Ver10.10.21+2
CVEListV5nec_corporation/univerge_ix-r/ix-vVer1.2.15 and earlier

🔴Vulnerability Details

2
CVEList
CVE-2024-11013: Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver92024-11-29
GHSA
GHSA-3qm6-wcp5-fx9f: Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver92024-11-29