CVE Published: 11/07/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: schneider |
Vendor: Schneider Electric |
Product: FoxRTU Station Status : PUBLISHED
CVE-2024-2602 Description
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\'Path
Traversal\') vulnerability exists that could result in remote code execution when an authenticated
user executes a saved project file that has been tampered by a malicious actor.
Metrics
CVSS Version: 3.1 |
Base Score: 7.3 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H