CVE-2024-5681: Input Validation
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5681?
CVE-2024-5681 has a high severity rating due to its potential for local denial-of-service and privilege escalation.
How do I fix CVE-2024-5681?
To fix CVE-2024-5681, update to versions of Schneider Electric's Ecostruxure Foxboro DCS Control Core Services that are higher than 9.8.
What systems are affected by CVE-2024-5681?
CVE-2024-5681 affects Schneider Electric's Ecostruxure Foxboro DCS Control Core Services up to version 9.8.
What type of attack does CVE-2024-5681 enable?
CVE-2024-5681 enables local denial-of-service attacks and potential privilege escalation through crafted IOCTL calls.
Who can exploit CVE-2024-5681?
CVE-2024-5681 can be exploited by a malicious actor who has local user access to the system.