First published: Wed Jun 12 2024(Updated: )
CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability exists that could cause escalation of privileges when an attacker abuses a limited admin account.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider-electric Spacelogic As-b Firmware | <6.0.1 | |
Schneider-electric Spacelogic As-b | ||
All of | ||
Schneider-electric Spacelogic As-p Firmware | <6.0.1 | |
Schneider-electric Spacelogic As-p |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5558 has been classified as a high severity vulnerability due to its potential for privilege escalation.
To mitigate CVE-2024-5558, update your Schneider Electric Spacelogic AS-B or AS-P firmware to the latest version beyond 6.0.1.
CVE-2024-5558 exploits a Time-of-check Time-of-use (TOCTOU) race condition which can allow limited admin accounts to escalate privileges.
CVE-2024-5558 affects Schneider Electric Spacelogic AS-B and AS-P firmware versions up to 6.0.1.
CVE-2024-5558 impacts the firmware of Schneider Electric Spacelogic devices, potentially affecting their security and functionality.