Security Advisory

CVE-2024-11013

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-11-29 08:03:07
Last updated 2025-07-24 14:40:37
Assigner NEC
CVSS score 7.2
State PUBLISHED

Description

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.