Incorrect default permissions in Schneider Electric products - CVE-2024-37038

 

Incorrect default permissions in Schneider Electric products - CVE-2024-37038

Published: April 23, 2025


Vulnerability identifier: #VU107864
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37038
CWE-ID: CWE-276
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to incorrect default permissions. A remote user can perform unauthorized file and firmware uploads when crafting custom web requests.


Affected software

Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum

How to mitigate CVE-2024-37038

Install updates from vendor's website.

Sage 1410 - update to C3414-500-S02K5_P9
Sage 1430 - update to C3414-500-S02K5_P9
Sage 1450 - update to C3414-500-S02K5_P9
Sage 2400 - update to C3414-500-S02K5_P9
Sage 4400 - update to C3414-500-S02K5_P9
Sage 3030 Magnum - update to C3414-500-S02K5_P9

External References

Related Security Bulletins