CVE-2024-2602

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user executes a saved project file that has been tampered by a malicious actor.
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:foxrtu_station:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-191-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-191-03.pdf - Vendor Advisory () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-191-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-191-03.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 7.3

12 Jul 2024, 16:39

Type Values Removed Values Added
First Time Schneider-electric foxrtu Station
Schneider-electric
CPE cpe:2.3:a:schneider-electric:foxrtu_station:*:*:*:*:*:*:*:*
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-191-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-191-03.pdf - () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-191-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-191-03.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 7.8

11 Jul 2024, 13:05

Type Values Removed Values Added
Summary
  • (es) CWE-22: Existe una vulnerabilidad de limitación inadecuada de un nombre de ruta a un directorio restringido ("Path Traversal") que podría provocar la ejecución remota de código cuando un usuario autenticado ejecuta un archivo de proyecto guardado que ha sido manipulado por un actor malintencionado.

11 Jul 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-11 09:15

Updated : 2024-11-21 09:10


NVD link : CVE-2024-2602

Mitre link : CVE-2024-2602

CVE.ORG link : CVE-2024-2602


JSON object : View

Products Affected

schneider-electric

  • foxrtu_station
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')