CVE-2024-37038: Schneider Electric Sage Rtu Firmware
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
Affected products
- Schneider Electric Sage Rtu Firmware: before c3414-500-s02k5_p9 (fixed in c3414-500-s02k5_p9)
Published 2024-06-12. Last modified 2026-06-17.