Description

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.

INFO

Published Date :

2024-06-12T16:51:55.800Z

Last Modified :

2024-08-02T03:43:50.738Z

Source :

schneider
AFFECTED PRODUCTS

The following products are affected by CVE-2024-37038 vulnerability.

Vendors Products
Schneider-electric
  • Sage 1410
  • Sage 1430
  • Sage 1450
  • Sage 2400
  • Sage 3030 Magnum
  • Sage 4400
  • Sage Rtu Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-37038.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact