First published: Wed Jun 12 2024(Updated: )
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider Electric Modicon M340 Firmware | ||
Schneider Electric Modicon M340 | ||
All of | ||
Schneider Electric BMXNOE0100 Firmware | ||
schneider-electric bmxnoe0100 | ||
All of | ||
schneider-electric BMXNOE0110H | ||
schneider-electric BMXNOE0110H |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5056 is a significant vulnerability that can disrupt firmware updates and webserver functionality.
To fix CVE-2024-5056, ensure that the affected files and directories are correctly configured and accessible for firmware updates.
CVE-2024-5056 affects Schneider Electric Modicon M340 firmware and other related devices.
The consequences of CVE-2024-5056 include the inability to update firmware and potential improper behavior of the webserver.
Currently, ensuring proper file system integrity may serve as a temporary workaround for CVE-2024-5056.