CVE-2024-5681
EUVD-2024-4685411.07.2024, 09:15
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| schneider-electric | ecostruxure_foxboro_dcs_control_core_services | 𝑥 ≤ 9.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration