Vulnerabilities > CVE-2024-37037 - Unspecified vulnerability in Schneider-Electric Sage RTU Firmware

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
schneider-electric

Summary

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.

Vulnerable Configurations

Part Description Count
OS
Schneider-Electric
29
Hardware
Schneider-Electric
6