CVE-2024-41889

Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pimax:play:*:*:*:*:*:*:*:*
cpe:2.3:a:pimax:pitool:-:*:*:*:*:*:*:*

History

30 Aug 2024, 17:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://pimax.com/pages/downloads-manuals - () https://pimax.com/pages/downloads-manuals - Product
References () https://jvn.jp/en/jp/JVN50850706/ - () https://jvn.jp/en/jp/JVN50850706/ - Third Party Advisory
References () https://github.com/OpenMAR/PiTool - () https://github.com/OpenMAR/PiTool - Product
CPE cpe:2.3:a:pimax:play:*:*:*:*:*:*:*:*
cpe:2.3:a:pimax:pitool:-:*:*:*:*:*:*:*
First Time Pimax pitool
Pimax play
Pimax
CWE NVD-CWE-Other

05 Aug 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-05 05:15

Updated : 2024-08-30 17:53


NVD link : CVE-2024-41889

Mitre link : CVE-2024-41889


JSON object : View

Products Affected

pimax

  • pitool
  • play