CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perform unauthorized file and firmware
uploads when crafting custom web requests.
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-06-12 17:15
Updated : 2024-07-25 20:25
NVD link : CVE-2024-37038
Mitre link : CVE-2024-37038
CVE.ORG link : CVE-2024-37038
JSON object : View
Products Affected
schneider-electric
- sage_1430
- sage_4400
- sage_1410
- sage_1450
- sage_rtu_firmware
- sage_2400
- sage_3030_magnum
CWE
CWE-276
Incorrect Default Permissions