CVE-2024-24782: Hima F-Com 01 Firmware

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.

Affected products

  • Hima F-Com 01 Firmware: up to and including 14.12
  • Hima F-CPU 01 Firmware: up to and including 14.16
  • Hima f30 03x Yy (com) Firmware: up to and including 24.14
  • Hima f30 03x Yy (cpu) Firmware: up to and including 18.6
  • Hima f35 03x Yy (com) Firmware: up to and including 24.14
  • Hima f35 03x Yy (cpu) Firmware: up to and including 18.6
  • Hima f60 CPU 03x Yy (com) Firmware: up to and including 24.14
  • Hima f60 CPU 03x Yy (cpu) Firmware: up to and including 18.6
  • Hima X-Com 01 E Yy Firmware: up to and including 15.14
  • Hima X-Com 01 Yy Firmware: up to and including 14.12
  • Hima X-CPU 01 Firmware: up to and including 14.16
  • Hima X-CPU 31 Firmware: up to and including 14.16
  • Hima X-Sb 01 Firmware: up to and including 7.54

Published 2024-02-13. Last modified 2026-06-17.