HomeDefault status
affected
24.04 (custom)
affected
24.17 (custom)
unaffected
Description
EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
24.04 (custom)
24.17 (custom)
Credits
Nick Guttilla, Mandiant
Neal Trischitta, Mandiant
References
github.com/...Disclosures/blob/master/2025/MNDT-2025-0002.md
www.enersys.com/...rate/cve/enersys_cve-2024-12442-final.pdf