Cyber Posture

CVE-2024-46603

High

Published: 07 January 2025

Published
07 January 2025
Modified
16 April 2025
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.0006 20.0th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.

Security Summary

CVE-2024-46603 is an XML External Entity (XXE) vulnerability, classified under CWE-611, affecting Elspec Engineering G5 Digital Fault Recorder Firmware version 1.2.1.12. The flaw enables attackers to process malicious XML payloads, leading to a Denial of Service (DoS) condition. It has a CVSS v3.1 base score of 7.5, rated as High severity, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility, low attack complexity, no privileges or user interaction required, and high impact on availability without affecting confidentiality or integrity.

Remote attackers without authentication can exploit this vulnerability by sending a specially crafted XML payload to the affected firmware. Successful exploitation disrupts the device's functionality, rendering the G5 Digital Fault Recorder unavailable and potentially impacting power system monitoring and fault recording operations in critical infrastructure environments.

Elspec Engineering provides details on this issue via their security advisory at https://www.elspec-ltd.com/support/security-advisories/. Security practitioners should consult this resource for recommended mitigations, such as firmware updates or configuration changes to address the XXE processing flaw.

Details

CWE(s)
CWE-611

Affected Products

elspec-ltd
g5dfr firmware
≤ 1.2.2.19

References