CVE-2024-50960

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:extron:sme_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:sme_211:-:*:*:*:*:*:*:*

History

25 Apr 2025, 18:35

Type Values Removed Values Added
CPE cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:sme_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:sme_211:-:*:*:*:*:*:*:*
First Time Extron sme 211 Firmware
Extron sme 211

22 Apr 2025, 18:00

Type Values Removed Values Added
First Time Extron smp 111
Extron smp 351 Firmware
Extron smp 211
Extron smp 351
Extron smp 111 Firmware
Extron smp 352 Firmware
Extron
Extron smp 352
Extron smp 211 Firmware
References () https://github.com/layer8secure/extron-smp-inject/ - () https://github.com/layer8secure/extron-smp-inject/ - Exploit, Third Party Advisory
References () https://ryanmroth.com/articles/exploiting-extron-smp-command-injection - () https://ryanmroth.com/articles/exploiting-extron-smp-command-injection - Exploit, Third Party Advisory
References () https://www.extron.com/article/smp - () https://www.extron.com/article/smp - Product
CPE cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:*

18 Apr 2025, 14:15

Type Values Removed Values Added
Summary (en) A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, and SMP 352 <= 2.16 allows a remote authenticated attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system. (en) A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

16 Apr 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CWE CWE-94
Summary
  • (es) Una vulnerabilidad de inyección de comandos en Nmap diagnostic tool in the admin web console of Extron SMP 111 &lt;=3.01, SMP 351 &lt;=2.16, and SMP 352 &lt;= 2.16 permite que un atacante remoto autenticado con privilegios administrativos ejecute comandos arbitrarios como root en el sistema operativo subyacente.

15 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 18:15

Updated : 2025-04-25 18:35


NVD link : CVE-2024-50960

Mitre link : CVE-2024-50960

CVE.ORG link : CVE-2024-50960


JSON object : View

Products Affected

extron

  • smp_111_firmware
  • smp_351
  • smp_111
  • smp_351_firmware
  • smp_352
  • sme_211_firmware
  • sme_211
  • smp_352_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')