CVE-2024-37037: Schneider Electric Sage Rtu Firmware
High severity, CVSS 8.1. EPSS: 1% chance of exploitation in the next 30 days.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
Affected products
- Schneider Electric Sage Rtu Firmware: before c3414-500-s02k5_p9 (fixed in c3414-500-s02k5_p9)
Published 2024-06-12. Last modified 2026-06-17.