First published: Wed Jun 12 2024(Updated: )
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider-electric Sage Rtu Firmware | <c3414-500-s02k5_p9 | |
Any of | ||
Schneider-electric Sage 1410 | ||
Schneider-electric Sage 1430 | ||
Schneider-electric Sage 1450 | ||
Schneider-electric Sage 2400 | ||
Schneider-electric Sage 3030 Magnum | ||
Schneider-electric Sage 4400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37039 has a moderate severity level due to its potential to cause denial of service.
CVE-2024-37039 can lead to a denial of service condition when an attacker sends a specially crafted HTTP request.
CVE-2024-37039 affects devices running Schneider Electric Sage RTU firmware versions prior to c3414-500-s02k5_p9.
Mitigation for CVE-2024-37039 can be achieved by updating the affected Schneider Electric Sage RTU firmware to a secure version.
While specific details on exploits for CVE-2024-37039 are not public, the vulnerability allows for denial of service attacks through crafted HTTP requests.