CVE-2024-37040: Schneider Electric Sage Rtu Firmware
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.
Affected products
- Schneider Electric Sage Rtu Firmware: before c3414-500-s02k5_p9 (fixed in c3414-500-s02k5_p9)
Published 2024-06-12. Last modified 2026-06-17.