CVE-2024-49396: Elvaco CME3100 Firmware

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersonate Elvaco and send false information.

Affected products

  • Elvaco CME3100 Firmware: version 1.12.1 only
  • Elvaco M-Bus Metering Gateway CME3100: version 1.12.1 only

Published 2024-10-17. Last modified 2026-06-17.