CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. See the original NVD description below for full technical details.
CVE
CVE-2024-47943
Severity
CRITICAL
CVSS
9.8
EPSS
0.64%
Original NVD Description
The firmware upgrade function in the admin web interface of the RittalĀ IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely available for download. This allows crafting malicious "signed" .patch files in order to compromise the device and execute arbitrary code.