Input validation error in Schneider Electric products - CVE-2024-11737

 

Input validation error in Schneider Electric products - CVE-2024-11737

Published: January 8, 2025


Vulnerability identifier: #VU102449
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11737
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary codeo n the system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.


Affected software

Modicon M241
Modicon M251
Modicon M258
Modicon LMC058

How to mitigate CVE-2024-11737

Install updates from vendor's website.


External References

Related Security Bulletins