CVE-2024-37040

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
12/06/2024
Last modified:
25/07/2024

Description

CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability<br /> exists that could allow a user with access to the device’s web interface to cause a fault on the<br /> device when sending a malformed HTTP request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:sage_rtu_firmware:*:*:*:*:*:*:*:* c3414-500-s02k5_p9 (excluding)
cpe:2.3:h:schneider-electric:sage_1410:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1430:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1450:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_2400:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_3030_magnum:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_4400:-:*:*:*:*:*:*:*