CVE-2024-6596

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
VendorProductVersion
endress\+hauserecho_curve_viewer_firmware
𝑥
≤ 5.2.2.6
endress\+hauserfieldcare_sfe500_package_usb_firmware
𝑥
≤ 1.40.00.7448
endress\+hauserfieldcare_sfe500_package_web-package_firmware
𝑥
≤ 1.40.00.7448
endress\+hauserfield_xpert_smt70_firmware
𝑥
≤ SMT70_Win10_LTSC_21H2_v1.07.00_RC02_01
endress\+hauserfield_xpert_smt50_firmware
𝑥
≤ SMT50_Win10_LTSC_21H2_v1.07.00_RC02_03
endress\+hauserfield_xpert_smt77_firmware
𝑥
≤ SMT77_Win10_SAC_22H2_v1.08.04_RC03_02
endress\+hauserfield_xpert_smt79_firmware
𝑥
≤ 1.08.02-1.8.8684.34292
endressecho_curve_viewer
𝑥
< 6.0.0
endressfieldcare_sfe500_package
𝑥
< 1.40.1
endressfield_xpert_smt79_firmware
-
endressfield_xpert_smt77_firmware
-
endressfield_xpert_smt70_firmware
-
endressfield_xpert_smt50_firmware
-
𝑥
= Vulnerable software versions