CVE-2024-47943: Rittal GmbH & Co. Kg IoT Interface & Cmc Iii Processing Unit
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely available for download. This allows crafting malicious "signed" .patch files in order to compromise the device and execute arbitrary code.
Affected products
- Rittal GmbH & Co. Kg IoT Interface & Cmc Iii Processing Unit: before 6.21.00.2 (fixed in 6.21.00.2)
Published 2024-10-15. Last modified 2026-06-17.