VYPR

Sage Rtu Firmware

by Schneider Electric

CVEs (6)

  • CVE-2024-37036CriJun 12, 2024
    risk 0.64cvss 9.8epss 0.01

    CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.

  • CVE-2024-37037HigJun 12, 2024
    risk 0.53cvss 8.1epss 0.01

    CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.

  • CVE-2024-37038HigJun 12, 2024
    risk 0.49cvss 7.5epss 0.00

    CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.

  • CVE-2024-37039MedJun 12, 2024
    risk 0.38cvss 5.9epss 0.01

    CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.

  • CVE-2024-5560MedJun 12, 2024
    risk 0.35cvss 5.3epss 0.01

    CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.

  • CVE-2024-37040MedJun 12, 2024
    risk 0.35cvss 5.4epss 0.00

    CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.