ZeroHour

CVE-2024-37038

CVSS 3.1
8.8 high
EPSS
<1%p31
Published
()
Modified
Description

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.

Vendors
schneider-electric
Products
sage rtu firmware
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.