« Volver al listado

CVE-2024-25552

Estado: AnalizadaAlta (7.8)—

A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-25552",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-25552",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-04T20:23:20.919936Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "W&T",
          "product": "Com Redirector PnP",
          "versions": [
            {
              "status": "affected",
              "version": "4.42"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "W&T",
          "product": "Com Redirector Legacy",
          "versions": [
            {
              "status": "affected",
              "version": "3.93"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "W&T",
          "product": "OPC-Server",
          "versions": [
            {
              "status": "affected",
              "version": "4.88"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:h:wut:com-redirector:*:*:*:*:*:*:*:*"
          ],
          "vendor": "wut",
          "product": "com-redirector",
          "versions": [
            {
              "status": "affected",
              "version": "4.42"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:h:wut:opc-server:*:*:*:*:*:*:*:*"
          ],
          "vendor": "wut",
          "product": "opc-server",
          "versions": [
            {
              "status": "affected",
              "version": "4.88"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-03-01T08:15:37.660",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2024-018",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2024-018",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-428"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product."
    },
    {
      "lang": "es",
      "value": "Un atacante local puede obtener privilegios administrativos insertando un archivo ejecutable en la ruta del producto afectado."
    }
  ],
  "lastModified": "2026-06-17T07:16:10.223",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wut:com_port_redirector_legacy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C890C2C9-28E6-4F6D-8D2A-184498864398",
              "versionEndIncluding": "3.93"
            },
            {
              "criteria": "cpe:2.3:a:wut:com_port_redirector_plug_\\&_play:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63B43D55-40DE-4854-BA22-0E63CE31D54A",
              "versionEndIncluding": "4.42"
            },
            {
              "criteria": "cpe:2.3:a:wut:opc_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E77CAEB4-8973-4B38-9F9A-6765498F7761",
              "versionEndIncluding": "4.88"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}