First published: Wed Nov 13 2024(Updated: )
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure IT Gateway | =1.21.0.6 | |
Schneider Electric EcoStruxure IT Gateway | =1.22.0.3 | |
Schneider Electric EcoStruxure IT Gateway | =1.22.1.5 | |
Schneider Electric EcoStruxure IT Gateway | =1.23.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10575 has a high severity level due to the risk of unauthorized access affecting connected devices.
To fix CVE-2024-10575, disable the affected feature that allows bypassing authorization in Schneider Electric EcoStruxure IT Gateway.
CVE-2024-10575 affects Schneider Electric EcoStruxure IT Gateway versions 1.21.0.6, 1.22.0.3, 1.22.1.5, and 1.23.0.4.
CVE-2024-10575 can result in unauthorized access to connected devices, leading to possible data breaches and operational disruptions.
Organizations can mitigate the risks of CVE-2024-10575 by applying available patches and ensuring proper authorization configurations are in place.