Vulnerability Details CVE-2024-41889
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-41889
-
-
-
cpe:2.3:a:pimax:play:1.17.01
-
cpe:2.3:a:pimax:play:1.18.02
-
cpe:2.3:a:pimax:play:1.18.03
-
cpe:2.3:a:pimax:play:1.20.03