CVE-2024-6596: Endress+Hauser: Multiple products are vulnerable to code injection
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6596?
CVE-2024-6596 is classified as a high-severity vulnerability due to the potential for unauthenticated remote code execution.
How do I fix CVE-2024-6596?
To fix CVE-2024-6596, users should upgrade to Endress Echo Curve Viewer version 6.0.0 or later and Endress Fieldcare Sfe500 Package version 1.40.1 or later.
Which software is affected by CVE-2024-6596?
CVE-2024-6596 affects Endress Echo Curve Viewer and Endress Fieldcare Sfe500 Package versions prior to specified releases.
What types of attacks are possible with CVE-2024-6596?
An attacker can run malicious C# code residing in curve files to execute arbitrary commands in the user's context.
Is there a workaround for CVE-2024-6596?
Currently, no specific workarounds are recommended for CVE-2024-6596; updating to the latest versions is the advised solution.