EnerSys AMPA Command Injection Vulnerability Leading to Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in EnerSys AMPA versions 24.04 through 24.16, inclusive. This vulnerability allows for privileged remote shell access. The issue arises on the Network Diagnostics webpage of Alpha XM3.1 and Alpha Gateway devices, enabling unauthenticated remote code execution.

Impact

Exploitation of this vulnerability allows for unauthorized remote code execution with elevated privileges.

Remediation

Users are advised to upgrade to EnerSys AMPA version 24.17. For Alpha XM3.1 Broadband UPS, upgrade to version 1.10.01 or later. For Alpha Gateway Firmware, upgrade to version 2.07.01 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.