CVE-2024-37038

EUVD-2024-36405
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perform unauthorized file and firmware
uploads when crafting custom web requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
schneider_electricsage_4400
𝑥
≤ c3414-500-s02k5_p8
ADP
schneider_electricsage_1430
𝑥
≤ c3414-500-s02k5_p8
ADP
schneider_electricsage_2400
𝑥
≤ c3414-500-s02k5_p8
ADP
schneider_electricsage_3030m
𝑥
≤ c3414-500-s02k5_p8
ADP
schneider_electricsage_1410
𝑥
≤ c3414-500-s02k5_p8
ADP
schneider_electricsage_1450
𝑥
≤ c3414-500-s02k5_p8
ADP