Buffer overflow in Schneider Electric products - CVE-2024-37040
Published: April 23, 2025
Vulnerability identifier: #VU107866
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-37040
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Schneider Electric
Affected software:
Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
Sage 1410
Sage 1430
Sage 1450
Sage 2400
Sage 4400
Sage 3030 Magnum
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A remote user can send a specially crafted HTTP request, trigger memory corruption and casue a denial of service condition on the target system.
How to mitigate CVE-2024-37040
Install updates from vendor's website.