CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
2024-06-12T17:15:51.080
2024-11-21T09:23:05.867
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | schneider-electric | sage_rtu_firmware | < c3414-500-s02k5_p9 | Yes |
Hardware | schneider-electric | sage_1410 | - | No |
Hardware | schneider-electric | sage_1430 | - | No |
Hardware | schneider-electric | sage_1450 | - | No |
Hardware | schneider-electric | sage_2400 | - | No |
Hardware | schneider-electric | sage_3030_magnum | - | No |
Hardware | schneider-electric | sage_4400 | - | No |