HomeDefault status
affected
Any version
affected
22.10 (custom)
unaffected
Description
EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
Any version
22.10 (custom)
References
github.com/...Disclosures/blob/master/2025/MNDT-2025-0001.md
www.enersys.com/...rate/cve/enersys_cve-2024-11861-final.pdf