CVE-2024-5680: Out-of-bounds Read
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5680?
CVE-2024-5680 has a severity classification that indicates it could lead to local denial-of-service under specific conditions.
How do I fix CVE-2024-5680?
To fix CVE-2024-5680, ensure that all vulnerable instances of Schneider Electric Ecostruxure Foxboro DCS Control Core Services are upgraded to version 9.9 or later.
What causes the CVE-2024-5680 vulnerability?
CVE-2024-5680 is caused by improper validation of array indices in the Foxboro.sys driver during IOCTL calls.
Who is affected by CVE-2024-5680?
CVE-2024-5680 affects users of Schneider Electric Ecostruxure Foxboro DCS Control Core Services versions up to 9.8.
Can CVE-2024-5680 be exploited remotely?
CVE-2024-5680 cannot be exploited remotely as it requires local user access to execute the malicious script or program.