First published: Wed Jun 12 2024(Updated: )
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider-electric Sage Rtu Firmware | <=c3414-500-s02k5_p8 | |
Any of | ||
Schneider-electric Sage 1410 | ||
Schneider-electric Sage 1430 | ||
Schneider-electric Sage 1450 | ||
Schneider-electric Sage 2400 | ||
Schneider-electric Sage 3030 Magnum | ||
Schneider-electric Sage 4400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37036 has a moderate severity level as it can lead to an authentication bypass.
To fix CVE-2024-37036, update the affected Schneider Electric Sage RTU firmware to a version released after c3414-500-s02k5_p8.
CVE-2024-37036 affects Schneider Electric Sage RTU firmware versions up to c3414-500-s02k5_p8.
CVE-2024-37036 is caused by an out-of-bounds write vulnerability that can be exploited with malformed POST requests.
Currently, a workaround for CVE-2024-37036 is not specified; updating the firmware is the recommended action.