Input validation error in Schneider Electric products - CVE-2024-11737
Published: January 8, 2025
Vulnerability identifier: #VU102449
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11737
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary codeo n the system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.
Affected software
Modicon M241
Modicon M251
Modicon M258
Modicon LMC058
Modicon M251
Modicon M258
Modicon LMC058
How to mitigate CVE-2024-11737
Install updates from vendor's website.