CVE-2024-50960

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*

History

22 Apr 2025, 18:00

Type Values Removed Values Added
References () https://github.com/layer8secure/extron-smp-inject/ - () https://github.com/layer8secure/extron-smp-inject/ - Exploit, Third Party Advisory
References () https://ryanmroth.com/articles/exploiting-extron-smp-command-injection - () https://ryanmroth.com/articles/exploiting-extron-smp-command-injection - Exploit, Third Party Advisory
References () https://www.extron.com/article/smp - () https://www.extron.com/article/smp - Product
First Time Extron
Extron smp 352 Firmware
Extron smp 211 Firmware
Extron smp 211
Extron smp 351
Extron smp 111
Extron smp 352
Extron smp 111 Firmware
Extron smp 351 Firmware
CPE cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:*

18 Apr 2025, 14:15

Type Values Removed Values Added
Summary (en) A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, and SMP 352 <= 2.16 allows a remote authenticated attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system. (en) A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

16 Apr 2025, 15:15

Type Values Removed Values Added
CWE CWE-94
Summary
  • (es) Una vulnerabilidad de inyección de comandos en Nmap diagnostic tool in the admin web console of Extron SMP 111 &lt;=3.01, SMP 351 &lt;=2.16, and SMP 352 &lt;= 2.16 permite que un atacante remoto autenticado con privilegios administrativos ejecute comandos arbitrarios como root en el sistema operativo subyacente.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

15 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 18:15

Updated : 2025-04-22 18:00


NVD link : CVE-2024-50960

Mitre link : CVE-2024-50960

CVE.ORG link : CVE-2024-50960


JSON object : View

Products Affected

extron

  • smp_111
  • smp_351_firmware
  • smp_211
  • smp_111_firmware
  • smp_351
  • smp_211_firmware
  • smp_352
  • smp_352_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')