CVE-2024-22811

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
22/04/2024
Last modified:
15/09/2025

Description

An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the Hostmot2 configuration cookie in the device memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tormach:pathpilot_controller:2.9.6:*:*:*:*:*:*:*
cpe:2.3:h:tormach:xstech_cnc_router:-:*:*:*:*:*:*:*