Path traversal in Schneider Electric products - CVE-2024-37037
Published: April 23, 2025
Vulnerability identifier: #VU107863
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-37037
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Schneider Electric
Affected software:
Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can send a specially crafted HTTP request to corrupt files and impact device functionality.
How to mitigate CVE-2024-37037
Install updates from vendor's website.