EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
History

Mon, 12 May 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 May 2025 22:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 09 May 2025 14:00:00 +0000

Type Values Removed Values Added
Description EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
Title Command injection in EnerSys AMPA 22.09 and prior versions
Weaknesses CWE-77
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Mandiant

Published: 2025-05-09T13:51:37.212Z

Updated: 2025-05-12T22:08:59.414Z

Reserved: 2024-11-27T13:56:42.420Z

Link: CVE-2024-11861

cve-icon Vulnrichment

Updated: 2025-05-12T22:08:33.393Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-09T14:15:36.807

Modified: 2025-05-12T22:15:19.207

Link: CVE-2024-11861

cve-icon Redhat

No data.