UTILITY sub-menu can allow a remote attacker to inject arbitrary
commands.
Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-40428 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands. |
Solution
Dover Fueling Solutions released a new software update version 4.19.10 for the MagLink LX console to address these vulnerabilities. The software release is available for installation on consoles through DFS's authorized service organizations in North America. North American users can reach DFS's customer support team by telephone at 877-679-8324.
Workaround
DFS strongly encourages users of MagLink products to: * Install MagLink consoles behind firewalls for security. * Monitor and install updates on a timely basis. * Contact DFS customer support with any questions about operations or updates of MagLink software. Alternatively, MagLink may operate offfline or disconnected from a network. Registered MagLink customers have access to technical information, updates, and technical bulletins via a DFS proprietary portal.
Tue, 01 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Doverfuelingsolutions progauge Maglink Lx4 Console
Doverfuelingsolutions progauge Maglink Lx4 Console Firmware Doverfuelingsolutions progauge Maglink Lx Console Doverfuelingsolutions progauge Maglink Lx Console Firmware |
|
CPEs | cpe:2.3:h:doverfuelingsolutions:progauge_maglink_lx4_console:-:*:*:*:*:*:*:* cpe:2.3:h:doverfuelingsolutions:progauge_maglink_lx_console:-:*:*:*:*:*:*:* cpe:2.3:o:doverfuelingsolutions:progauge_maglink_lx4_console_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:doverfuelingsolutions:progauge_maglink_lx_console_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Doverfuelingsolutions progauge Maglink Lx4 Console
Doverfuelingsolutions progauge Maglink Lx4 Console Firmware Doverfuelingsolutions progauge Maglink Lx Console Doverfuelingsolutions progauge Maglink Lx Console Firmware |
Wed, 25 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Doverfuelingsolutions
Doverfuelingsolutions maglink Lx4 Console Doverfuelingsolutions maglink Lx Console |
|
CPEs | cpe:2.3:a:doverfuelingsolutions:maglink_lx4_console:*:*:*:*:*:*:*:* cpe:2.3:a:doverfuelingsolutions:maglink_lx_console:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Doverfuelingsolutions
Doverfuelingsolutions maglink Lx4 Console Doverfuelingsolutions maglink Lx Console |
|
Metrics |
ssvc
|
Wed, 25 Sep 2024 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands. | |
Title | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command Injection | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-25T16:55:33.557Z
Reserved: 2024-09-05T20:11:00.339Z
Link: CVE-2024-43693

Updated: 2024-09-25T16:55:22.149Z

Status : Analyzed
Published: 2024-09-25T01:15:43.370
Modified: 2024-10-01T17:17:16.107
Link: CVE-2024-43693

No data.

No data.