CVE-2024-51330

medium

Description

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and transmission components, Ultimaker 3D Printers.

References

https://gist.github.com/HalaAli198/ff06d7a94c06cdfb821dec4d6303e01b

Details

Source: Mitre, NVD

Published: 2024-11-15

Updated: 2024-11-27

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 4.4

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Severity: Medium

EPSS

EPSS: 0.00081