CVE-2024-5559Active Exploitation(schneider-electric / powerlogic_p5)

HIGHCVSS 6.8 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch schneider-electric powerlogic_p5 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-327

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • powerlogic_p5
  • powerlogic_p5_firmware

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Products
powerlogic_p5powerlogic_p5_firmware

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-11: 2PoC Mentioned / Linked · 2026-08-11: 1Exploit Tool / Code · 2026-08-11: 1Active Exploitation · 2026-08-11: 2Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 108-11
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets3 URLs
By indicator
Full discourse2 posts
  • Jim Nitterauer 🇺🇸@JNitterauer
    Active Exploitation

    US, South Korea and allied agencies warn: Gunra ransomware is breaching critical infrastructure via Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) edge flaws, then defeating MFA at the VDI portal. Patch your edge. #ransomware #Fortinet

    Post summary

    Gunra ransomware is actively exploiting CVE-2025-24472 (Fortinet) and CVE-2024-5559 (Schneider Electric) to breach critical infrastructure, prompting agencies to advise patching edge devices.

    01021208
    8.5K followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    Gunra Linux ransomware bakes in weak key derivation that lets anyone with a sample pull the full Salsa20 or ChaCha20 key in seconds. Access starts with CVE-2024-5559 on Schneider Electric PowerLogic P5 and CVE-2025-24472 on FortiOS 7.2.0–7.4.4 plus FortiProxy. RaaS panel hands operators a builder and separate Linux lockers; observed jobs reached 9 TB. Lateral movement runs http://impacket-psexec.py -hashes user@target plus http://smbclient.py shares, then http://secretsdump.py -ntds NTDS.dit. Exfil pushes main.exe output to OneDrive or SharePoint, MEGA for the larger archives. MFA bypass edits VDI portal files and re-uses stolen SSL-VPN cookies by swapping the session token before the server checks. Watch for odd Impacket SMB traffic and sudden cookie reuse on Fortinet endpoints.

    Post summary

    Gunra ransomware is actively exploiting CVE-2024-5559 and CVE-2025-24472 through weak key derivation, employing impacket, smbclient, and secretsdump tools, and has been observed participating in large‑scale RaaS operations.

    0000195
    162 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWschneider-electricpowerlogic_p5---
OSschneider-electricpowerlogic_p5_firmware---

Explore more