First published: Wed Jun 12 2024(Updated: )
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider-electric Sage Rtu Firmware | <c3414-500-s02k5_p9 | |
Any of | ||
Schneider-electric Sage 1410 | ||
Schneider-electric Sage 1430 | ||
Schneider-electric Sage 1450 | ||
Schneider-electric Sage 2400 | ||
Schneider-electric Sage 3030 Magnum | ||
Schneider-electric Sage 4400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37037 has been assessed as a significant vulnerability due to its potential to allow authenticated users to corrupt files via crafted HTTP requests.
To mitigate CVE-2024-37037, ensure that proper access restrictions are in place for the web interface and validate all user inputs.
CVE-2024-37037 affects Schneider Electric Sage RTU firmware versions up to but not including c3414-500-s02k5_p9.
Yes, exploiting CVE-2024-37037 can corrupt files which may impact the functionality of the affected device.
Exploitation of CVE-2024-37037 requires authentication, as it targets authenticated users with access to the device’s web interface.