CVE-2024-5679: High severity Schneider-electric Ecostruxure Foxboro Dcs Control Core Services vulnerability
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5679?
CVE-2024-5679 is considered to have a high severity rating due to its potential for local denial-of-service and kernel memory leaks.
How do I fix CVE-2024-5679?
To fix CVE-2024-5679, it is recommended to apply the latest security patches provided by Schneider Electric for the affected software.
What systems are affected by CVE-2024-5679?
CVE-2024-5679 affects versions up to 9.8 of Schneider Electric's Ecostruxure Foxboro DCS Control Core Services.
Can CVE-2024-5679 be exploited remotely?
CVE-2024-5679 cannot be exploited remotely as it requires local user access to the system.
What are the potential impacts of CVE-2024-5679?
The potential impacts of CVE-2024-5679 include local denial-of-service scenarios and exposure of kernel memory content.