First published: Wed Jun 12 2024(Updated: )
CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider-electric Sage Rtu Firmware | <c3414-500-s02k5_p9 | |
Any of | ||
Schneider-electric Sage 1410 | ||
Schneider-electric Sage 1430 | ||
Schneider-electric Sage 1450 | ||
Schneider-electric Sage 2400 | ||
Schneider-electric Sage 3030 Magnum | ||
Schneider-electric Sage 4400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5560 has a severity rating that indicates the risk of denial of service due to out-of-bounds read vulnerability.
To fix CVE-2024-5560, update the affected Schneider Electric Sage RTU firmware to the latest version available beyond c3414-500-s02k5_p9.
CVE-2024-5560 affects devices running Schneider Electric Sage RTU firmware versions up to c3414-500-s02k5_p9.
Yes, an attacker can exploit CVE-2024-5560 remotely by sending specially crafted HTTP requests to the device's web interface.
The potential impact of CVE-2024-5560 includes a denial of service, which can disrupt access to the device's web interface.