Critical severity10.0NVD Advisory· Published Oct 23, 2024· Updated Jun 17, 2026
CVE-2024-47901
CVE-2024-47901
Description
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not sanitize the input parameters in specific GET requests that allow for code execution on operating system level. In combination with other vulnerabilities (CVE-2024-47902, CVE-2024-47903, CVE-2024-47904) this could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:siemens:intermesh_7177_hybrid_2.0_subscriber:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:siemens:intermesh_7177_hybrid_2.0_subscriber:*:*:*:*:*:*:*:*range: <8.2.12
- (no CPE)range: 0
cpe:2.3:o:siemens:intermesh_7707_fire_subscriber_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:siemens:intermesh_7707_fire_subscriber_firmware:*:*:*:*:*:*:*:*range: <7.2.12
- (no CPE)range: 0
- Range: <V8.2.12
- Range: <V7.2.12
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/html/ssa-333468.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.