CVE-2024-50960 is a command injection vulnerability found in the Nmap diagnostic tool within the admin web console of Extron SMP 111, SMP 351, SMP 352, and SME 211 devices. This allows a remote, authenticated attacker to execute arbitrary commands as root on the underlying operating system. Rated with a CVSS score of 7.2 (High), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.01CPE matchmatch criteria | cpe:2.3:o:extron:smp_111_firmware:*:*:*:*:*:*:*:* | ||
<= 2.16CPE matchmatch criteria | cpe:2.3:o:extron:smp_351_firmware:*:*:*:*:*:*:*:* | ||
<= 2.16CPE matchmatch criteria | cpe:2.3:o:extron:smp_352_firmware:*:*:*:*:*:*:*:* | ||
<= 3.02CPE matchmatch criteria | cpe:2.3:o:extron:sme_211_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.