# CVE-2024-47944

## Summary

- **CVE ID:** CVE-2024-47944
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-1299
- **Published:** Oct 15, 2024
- **Last Modified:** Mar 13, 2026

## Description

The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via the firmware upgrade function.

## Affected Products

- RITTAL GmbH & Co. KG — IoT Interface & CMC III Processing Unit (<6.21.00.2)

## References

- [CNA](https://r.sec-consult.com/rittaliot)
- [CNA](https://www.rittal.com/de-de/products/deep/3124300)
- [CVE](http://seclists.org/fulldisclosure/2024/Oct/4)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.40%
- **EPSS Percentile:** 33.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._