cbcvebase.
CVE-2024-37038
published 2024-06-12

CVE-2024-37038: CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform…

PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.37%
29.5th percentile
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.

Affected

7 ranges
VendorProductVersion rangeFixed in
schneider-electricsage_rtu_firmware< c3414-500-s02k5_p9c3414-500-s02k5_p9
schneider_electricsage_1410
schneider_electricsage_1430
schneider_electricsage_1450
schneider_electricsage_2400
schneider_electricsage_3030_magnum
schneider_electricsage_4400
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.