Back to search
CVE-2024-47944
Published: Oct 15, 2024
Modified: Nov 3, 2025
PUBLISHED
Description
The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via the firmware upgrade function.
| Vendor | Product | Versions |
|---|---|---|
RITTAL GmbH & Co. KG | IoT Interface & CMC III Processing Unit | affected <6.21.00.2 |
Weaknesses (CWE)
References
https://r.sec-consult.com/rittaliot
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now