Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "07" allows a local attacker to execute arbitrary code by saving a malicious file to a specific folder. As a result, the attacker may disclose, tamper with, destroy or delete information in the product, or cause a denial-of-service (DoS) condition on the product.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32472 Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "07" allows a local attacker to execute arbitrary code by saving a malicious file to a specific folder. As a result, the attacker may disclose, tamper with, destroy or delete information in the product, or cause a denial-of-service (DoS) condition on the product.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published:

Updated: 2024-08-01T20:26:57.118Z

Reserved: 2024-04-17T02:56:01.539Z

Link: CVE-2024-3904

cve-icon Vulnrichment

Updated: 2024-08-01T20:26:57.118Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-04T09:15:04.317

Modified: 2024-11-21T09:30:39.910

Link: CVE-2024-3904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses