Out-of-bounds write in Schneider Electric products - CVE-2024-37036
Published: April 23, 2025
Vulnerability identifier: #VU107862
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-37036
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Schneider Electric
Affected software:
Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can send a specially crafted POST request, trigger an out-of-bounds write and execute arbitrary code on the target system.
How to mitigate CVE-2024-37036
Install updates from vendor's website.