Description
EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
24.04 (custom)
24.17 (custom)
Credits
Nick Guttilla, Mandiant
Neal Trischitta, Mandiant
References
github.com/...Disclosures/blob/master/2025/MNDT-2025-0002.md
www.enersys.com/...rate/cve/enersys_cve-2024-12442-final.pdf