CVE-2024-11013
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
29/11/2024
Last modified:
23/07/2025
Description
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH



