A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.
References
Link | Resource |
---|---|
https://github.com/layer8secure/extron-smp-inject/ | Exploit Third Party Advisory |
https://ryanmroth.com/articles/exploiting-extron-smp-command-injection | Exploit Third Party Advisory |
https://www.extron.com/article/smp | Product |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
22 Apr 2025, 18:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/layer8secure/extron-smp-inject/ - Exploit, Third Party Advisory | |
References | () https://ryanmroth.com/articles/exploiting-extron-smp-command-injection - Exploit, Third Party Advisory | |
References | () https://www.extron.com/article/smp - Product | |
First Time |
Extron
Extron smp 352 Firmware Extron smp 211 Firmware Extron smp 211 Extron smp 351 Extron smp 111 Extron smp 352 Extron smp 111 Firmware Extron smp 351 Firmware |
|
CPE | cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:* cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:* cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:* cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:* cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:* |
18 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system. |
16 Apr 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 | |
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
15 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-15 18:15
Updated : 2025-04-22 18:00
NVD link : CVE-2024-50960
Mitre link : CVE-2024-50960
CVE.ORG link : CVE-2024-50960
JSON object : View
Products Affected
extron
- smp_111
- smp_351_firmware
- smp_211
- smp_111_firmware
- smp_351
- smp_211_firmware
- smp_352
- smp_352_firmware
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')