Description
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47661 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en/advisories/VDE-2024-041 |
|
History
Tue, 01 Oct 2024 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Endress
Endress echo Curve Viewer Endress field Xpert Smt50 Endress field Xpert Smt50 Firmware Endress field Xpert Smt70 Endress field Xpert Smt70 Firmware Endress field Xpert Smt77 Endress field Xpert Smt77 Firmware Endress field Xpert Smt79 Endress field Xpert Smt79 Firmware Endress fieldcare Sfe500 Package |
|
| CPEs | cpe:2.3:a:endress:echo_curve_viewer:*:*:*:*:*:*:*:* cpe:2.3:a:endress:fieldcare_sfe500_package:*:*:*:*:*:*:*:* cpe:2.3:h:endress:field_xpert_smt50:-:*:*:*:*:*:*:* cpe:2.3:h:endress:field_xpert_smt70:-:*:*:*:*:*:*:* cpe:2.3:h:endress:field_xpert_smt77:-:*:*:*:*:*:*:* cpe:2.3:h:endress:field_xpert_smt79:-:*:*:*:*:*:*:* cpe:2.3:o:endress:field_xpert_smt50_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:endress:field_xpert_smt70_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:endress:field_xpert_smt77_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:endress:field_xpert_smt79_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Endress
Endress echo Curve Viewer Endress field Xpert Smt50 Endress field Xpert Smt50 Firmware Endress field Xpert Smt70 Endress field Xpert Smt70 Firmware Endress field Xpert Smt77 Endress field Xpert Smt77 Firmware Endress field Xpert Smt79 Endress field Xpert Smt79 Firmware Endress fieldcare Sfe500 Package |
Tue, 10 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Endress\+hauser
Endress\+hauser echo Curve Viewer Firmware Endress\+hauser field Xpert Smt50 Firmware Endress\+hauser field Xpert Smt70 Firmware Endress\+hauser field Xpert Smt77 Firmware Endress\+hauser field Xpert Smt79 Firmware Endress\+hauser fieldcare Sfe500 Package Usb Firmware Endress\+hauser fieldcare Sfe500 Package Web-package Firmware |
|
| CPEs | cpe:2.3:o:endress\+hauser:echo_curve_viewer_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:endress\+hauser:field_xpert_smt50_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:endress\+hauser:field_xpert_smt70_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:endress\+hauser:field_xpert_smt77_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:endress\+hauser:field_xpert_smt79_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:endress\+hauser:fieldcare_sfe500_package_usb_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:endress\+hauser:fieldcare_sfe500_package_web-package_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Endress\+hauser
Endress\+hauser echo Curve Viewer Firmware Endress\+hauser field Xpert Smt50 Firmware Endress\+hauser field Xpert Smt70 Firmware Endress\+hauser field Xpert Smt77 Firmware Endress\+hauser field Xpert Smt79 Firmware Endress\+hauser fieldcare Sfe500 Package Usb Firmware Endress\+hauser fieldcare Sfe500 Package Web-package Firmware |
|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | |
| Title | Endress+Hauser: Multiple products are vulnerable to code injection | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Endress
Subscribe
Echo Curve Viewer
Subscribe
Field Xpert Smt50
Subscribe
Field Xpert Smt50 Firmware
Subscribe
Field Xpert Smt70
Subscribe
Field Xpert Smt70 Firmware
Subscribe
Field Xpert Smt77
Subscribe
Field Xpert Smt77 Firmware
Subscribe
Field Xpert Smt79
Subscribe
Field Xpert Smt79 Firmware
Subscribe
Fieldcare Sfe500 Package
Subscribe
Endress\+hauser
Subscribe
Echo Curve Viewer Firmware
Subscribe
Field Xpert Smt50 Firmware
Subscribe
Field Xpert Smt70 Firmware
Subscribe
Field Xpert Smt77 Firmware
Subscribe
Field Xpert Smt79 Firmware
Subscribe
Fieldcare Sfe500 Package Usb Firmware
Subscribe
Fieldcare Sfe500 Package Web-package Firmware
Subscribe
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-09-10T18:46:17.099Z
Reserved: 2024-07-09T08:00:06.415Z
Link: CVE-2024-6596
Updated: 2024-09-10T18:45:27.313Z
Status : Analyzed
Published: 2024-09-10T08:15:03.350
Modified: 2024-10-01T12:26:45.967
Link: CVE-2024-6596
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD