CVE-2024-37038
published 2024-06-12CVE-2024-37038: CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.37%
29.5th percentile
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perform unauthorized file and firmware
uploads when crafting custom web requests.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | sage_rtu_firmware | < c3414-500-s02k5_p9 | c3414-500-s02k5_p9 |
| schneider_electric | sage_1410 | — | — |
| schneider_electric | sage_1430 | — | — |
| schneider_electric | sage_1450 | — | — |
| schneider_electric | sage_2400 | — | — |
| schneider_electric | sage_3030_magnum | — | — |
| schneider_electric | sage_4400 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Sage Series
cisa_ics·2025-04-17·CVSS 9.8
[CRITICAL] Schneider Electric Sage Series
ICS Advisory
##
Schneider Electric Sage Series
Release DateApril 17, 2025
Alert CodeICSA-25-107-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: Sage series
- Vulnerabilities: Out-of-bounds Write, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Default Permissions, Unchecked Return Value, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to compromise the impacted device, leading to loss of data, lo
GHSA
GHSA-f3h5-qqxj-cvgg: CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perfor
ghsa_unreviewed·2024-06-12
CVE-2024-37038 [HIGH] CWE-276 GHSA-f3h5-qqxj-cvgg: CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perfor
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perform unauthorized file and firmware
uploads when crafting custom web requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-12
Published