CVE-2024-37037

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
12/06/2024
Last modified:
25/07/2024

Description

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path<br /> Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s<br /> web interface to corrupt files and impact device functionality when sending a crafted HTTP<br /> request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:sage_rtu_firmware:*:*:*:*:*:*:*:* c3414-500-s02k5_p9 (excluding)
cpe:2.3:h:schneider-electric:sage_1410:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1430:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1450:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_2400:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_3030_magnum:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_4400:-:*:*:*:*:*:*:*