CVE-2024-10575
CRITICALDescription
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| schneider-electric | ecostruxure_it_gateway |
| schneider-electric | ecostruxure_it_gateway |
| schneider-electric | ecostruxure_it_gateway |
| schneider-electric | ecostruxure_it_gateway |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-10575? +
How severe is CVE-2024-10575? +
What products are affected by CVE-2024-10575? +
How do I check if I'm vulnerable to CVE-2024-10575? +
Related Vulnerabilities
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` …
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with …
The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any …
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role …
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data …