CVE Published: 12/06/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: schneider |
Vendor: Schneider Electric |
Product: Sage 1410 Status : PUBLISHED
CVE-2024-37038 Description
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perform unauthorized file and firmware
uploads when crafting custom web requests.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H