CVE-2024-37038

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:sage_rtu_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:schneider-electric:sage_1410:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1430:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_1450:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_2400:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_3030_magnum:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:sage_4400:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-06-12 17:15

Updated : 2024-07-25 20:25


NVD link : CVE-2024-37038

Mitre link : CVE-2024-37038

CVE.ORG link : CVE-2024-37038


JSON object : View

Products Affected

schneider-electric

  • sage_1430
  • sage_4400
  • sage_1410
  • sage_1450
  • sage_rtu_firmware
  • sage_2400
  • sage_3030_magnum
CWE
CWE-276

Incorrect Default Permissions