Vulnerability CVE-2024-25136


Published: 2024-03-26   Modified: 2024-03-27

Description:

There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.

Type:

CWE-22

(Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

 References:
https://https://www.cisa.gov/news-events/ics-advisories/icsa-24-086-01

Copyright 2026, cxsecurity.com

 

Back to Top