Unchecked Return Value in Schneider Electric products - CVE-2024-37039
Published: April 23, 2025
Vulnerability identifier: #VU107865
CSH Severity: High
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-37039
CWE-ID: CWE-252
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to unchecked return value. A remote attacker can send a specially crafted HTTP request and perform a denial of service (DoS) attack.
Affected software
Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
How to mitigate CVE-2024-37039
Install updates from vendor's website.
Sage 1410 - update to C3414-500-S02K5_P9
Sage 1430 - update to C3414-500-S02K5_P9
Sage 1450 - update to C3414-500-S02K5_P9
Sage 2400 - update to C3414-500-S02K5_P9
Sage 4400 - update to C3414-500-S02K5_P9
Sage 3030 Magnum - update to C3414-500-S02K5_P9
Sage 1430 - update to C3414-500-S02K5_P9
Sage 1450 - update to C3414-500-S02K5_P9
Sage 2400 - update to C3414-500-S02K5_P9
Sage 4400 - update to C3414-500-S02K5_P9
Sage 3030 Magnum - update to C3414-500-S02K5_P9