CVE-2024-37037

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:sage_rtu_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:sage_1410:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1430:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1450:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_2400:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_3030_magnum:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_4400:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-06-12 17:15

Updated : 2024-07-25 20:25


NVD link : CVE-2024-37037

Mitre link : CVE-2024-37037

CVE.ORG link : CVE-2024-37037


JSON object : View

Products Affected

schneider-electric

  • sage_1430
  • sage_4400
  • sage_1410
  • sage_1450
  • sage_rtu_firmware
  • sage_2400
  • sage_3030_magnum
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')