CVE-2024-37038

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/06/2024
Last modified:
25/07/2024

Description

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated<br /> user with access to the device’s web interface to perform unauthorized file and firmware<br /> uploads when crafting custom web requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:sage_rtu_firmware:*:*:*:*:*:*:*:* c3414-500-s02k5_p9 (excluding)
cpe:2.3:h:schneider-electric:sage_1410:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1430:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1450:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_2400:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_3030_magnum:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_4400:-:*:*:*:*:*:*:*