Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37040


CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.


Published

2024-06-12T17:15:51.540

Last Modified

2024-11-21T09:23:06.170

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric sage_rtu_firmware < c3414-500-s02k5_p9 Yes
Hardware schneider-electric sage_1410 - No
Hardware schneider-electric sage_1430 - No
Hardware schneider-electric sage_1450 - No
Hardware schneider-electric sage_2400 - No
Hardware schneider-electric sage_3030_magnum - No
Hardware schneider-electric sage_4400 - No

References