CVE-2024-8938
published 2024-11-13CVE-2024-8938: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution…
PriorityP345high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.52%
40.5th percentile
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a
crafted Modbus function call to tamper with memory area involved in memory size computation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| schneider_electric | modicon_m340_cpu | — | — |
| schneider_electric | modicon_mc80 | — | — |
| schneider_electric | modicon_momentum_unity_m1e_processor | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_apache4.6
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fv43-v7vc-rjjf: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code exec
ghsa_unreviewed·2024-11-13
CVE-2024-8938 [CRITICAL] CWE-119 GHSA-fv43-v7vc-rjjf: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code exec
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could
cause a potential arbitrary code execution after a successful Man-In-The-Middle attack followed by sending a
crafted Modbus function call to tamper with memory area involved in memory size computation.
CISA ICS
Schneider Electric Modicon M340, MC80, and Momentum Unity M1E (Update B)
cisa_ics·2026-01-20·CVSS 8.3
[HIGH] Schneider Electric Modicon M340, MC80, and Momentum Unity M1E (Update B)
ICS Advisory
##
Schneider Electric Modicon M340, MC80, and Momentum Unity M1E (Update B)
Last RevisedJanuary 20, 2026
Alert CodeICSA-24-326-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Schneider Electric is aware of multiple vulnerabilities in its Modicon Controllers M340 / Momentum / MC80 products.Modicon PAC control and monitor industrial operations.Failure to apply the provided remediations/mitigations below may risk unauthorized access to the controller, which could result in the possibility of denial of service and loss of confidentiality, integrity of the controller.January 2026 Update: Remediation is now available for Modicon MC80.
The following versions of Schneider Electric Modicon M34
Apache
Apache nifi: CVE-2024-37389
vendor_apache·CVSS 4.6
CVE-2024-37389 Apache nifi: CVE-2024-37389
Apache nifi: CVE-2024-37389
Title: Improper Neutralization of Input in Parameter Context Description Published: 2024-07-08 Severity: Medium Products: Apache NiFi Affected Versions: 1.10.0 to 1.26.0 and 2.0.0-M1 to 2.0.0-M3 Fixed Versions: 1.27.0 and 2.0.0-M4 Reporter: Akbar Kustirama at abay.sh, GitHub user abaykan References CVE Record: CVE-2024-37389 NVD Record: CVE-2024-37389 Apache Jira Issue: NIFI-13374 GitHub Pull Request: 8938 Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context configuration that is vulnerable to cross-site scripting. An authenticated user, authorized to configure a Parameter Context, can enter arbitrary JavaScript code, which the client browser will execute within the session context of the authentica
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-13
Published