CVE-2024-10037: Null Pointer Dereference
A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted message sequence is executed on a WebSocket connection. An attacker must be properly authenticated and the test mode function of RTU500 must be enabled to exploit this vulnerability.
The affected CMU will automatically recover itself if an attacker successfully exploits this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10037?
CVE-2024-10037 has a critical severity level as it can lead to denial of service for the RTU500 CMU application.
How do I fix CVE-2024-10037?
To remediate CVE-2024-10037, ensure that the test mode function of the RTU500 is disabled and monitor WebSocket connections for suspicious activity.
What component is affected by CVE-2024-10037?
CVE-2024-10037 affects the RTU500 web server component specifically related to the RTU500 CMU application.
Who is vulnerable to CVE-2024-10037?
Only authenticated users with access to the RTU500 CMU application and enabled test mode are vulnerable to CVE-2024-10037.
What type of attack does CVE-2024-10037 involve?
CVE-2024-10037 involves a denial of service attack through specially crafted message sequences over WebSocket connections.