CVE-2024-2602: Path Traversal
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2602?
CVE-2024-2602 is considered critical as it allows for remote code execution due to path traversal vulnerabilities.
How do I fix CVE-2024-2602?
To address CVE-2024-2602, update Schneider Electric FoxRTU Station to version 9.3.0 or later.
Who is affected by CVE-2024-2602?
CVE-2024-2602 affects users of Schneider Electric FoxRTU Station versions prior to 9.3.0.
What are the potential consequences of CVE-2024-2602?
Exploiting CVE-2024-2602 could allow an attacker to execute arbitrary code remotely, potentially compromising the system.
Is authentication required to exploit CVE-2024-2602?
Yes, exploitation of CVE-2024-2602 requires an authenticated user to execute the tampered project file.