CVE-2024-24578 is a critical unauthenticated remote code execution (RCE) vulnerability affecting RaspberryMatic and OCCU prior to version 3.75.6.20240316. This flaw stems from multiple issues within the Java-based HMIPServer.jar component, specifically the FirmwareController class lacking session ID checks, allowing unauthorized access. With a CVSS score of 9.8 (CRITICAL), an attacker can achieve full system compromise as the root user over the network with low attack complexity. While not currently on CISA's KEV catalog, a Metasploit module exists, indicating readily available exploit code, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.75.6.20240316CPE matchmatch criteria | cpe:2.3:o:raspberrymatic:raspberrymatic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.