CVE-2024-5681
11.07.2024, 09:15
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | ecostruxure_foxboro_dcs_control_core_services | 𝑥 ≤ 9.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration