CVE-2024-0865: High severity schneider electric ecostruxure it gateway vulnerability
Published Jun 12, 2024
·Updated
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
Affected Software
1 affected component
Schneider-electric Ecostruxure It Gateway<1.21.0
Event History
Jun 12, 2024
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0865?
CVE-2024-0865 has a high severity due to its potential for local privilege escalation.
2
How do I fix CVE-2024-0865?
To fix CVE-2024-0865, update your Schneider Electric EcoStruxure IT Gateway to version 1.21.0 or later.
3
What causes the CVE-2024-0865 vulnerability?
CVE-2024-0865 is caused by the use of hard-coded credentials in the affected software.
4
Who is affected by CVE-2024-0865?
CVE-2024-0865 affects users of Schneider Electric EcoStruxure IT Gateway versions prior to 1.21.0.
5
What potential impact does CVE-2024-0865 have?
CVE-2024-0865 could allow a non-administrative user to escalate their privileges on the system.