ZeroHour

CVE-2024-6596

CVSS 3.1
9.8 critical
EPSS
<1%p54
Published
()
Modified
Description

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

Vendors
endress
Products
echo curve viewer, fieldcare sfe500 package, field xpert smt79 firmware, field xpert smt77 firmware, field xpert smt70 firmware, field xpert smt50 firmware
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.