A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.
History

Fri, 25 Apr 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Extron sme 211
Extron sme 211 Firmware
CPEs cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:extron:sme_211:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:sme_211_firmware:*:*:*:*:*:*:*:*
Vendors & Products Extron smp 211
Extron smp 211 Firmware
Extron sme 211
Extron sme 211 Firmware

Tue, 22 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Extron
Extron smp 111
Extron smp 111 Firmware
Extron smp 211
Extron smp 211 Firmware
Extron smp 351
Extron smp 351 Firmware
Extron smp 352
Extron smp 352 Firmware
CPEs cpe:2.3:h:extron:smp_111:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_211:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_351:-:*:*:*:*:*:*:*
cpe:2.3:h:extron:smp_352:-:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:*
Vendors & Products Extron
Extron smp 111
Extron smp 111 Firmware
Extron smp 211
Extron smp 211 Firmware
Extron smp 351
Extron smp 351 Firmware
Extron smp 352
Extron smp 352 Firmware

Fri, 18 Apr 2025 13:45:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, and SMP 352 <= 2.16 allows a remote authenticated attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system. A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

Wed, 16 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 17:45:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, and SMP 352 <= 2.16 allows a remote authenticated attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-04-15T00:00:00.000Z

Updated: 2025-04-18T13:25:21.966Z

Reserved: 2024-10-28T00:00:00.000Z

Link: CVE-2024-50960

cve-icon Vulnrichment

Updated: 2025-04-16T14:14:05.708Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-15T18:15:45.263

Modified: 2025-04-25T18:35:24.457

Link: CVE-2024-50960

cve-icon Redhat

No data.