# CVE-2024-12430

## Summary

- **CVE ID:** CVE-2024-12430
- **Severity:** HIGH
- **CVSS Score:** 7.3 (CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-280
- **Published:** Jan 7, 2025
- **Last Modified:** Mar 13, 2026

## Description

An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject arbitrary commands into a specifically crafted file, which then will be executed by root user.
All AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.

## Affected Products

- ABB — AC500 V3 (0)

## References

- [CNA](https://search.abb.com/library/Download.aspx?DocumentID=3ADR011377&LanguageCode=en&DocumentPartId=&Action=Launch)
- [CVE](http://seclists.org/fulldisclosure/2025/Jan/5)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 26.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._