Security Advisory

CVE-2024-10776

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-12-06 12:38:55
Last updated 2024-12-09 14:06:40
Assigner SICK AG
State PUBLISHED

Description

Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write files or load apps that use all features of the product available to a customer.