Description
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
Published: 2024-09-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-47661 An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
History

Tue, 01 Oct 2024 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Endress
Endress echo Curve Viewer
Endress field Xpert Smt50
Endress field Xpert Smt50 Firmware
Endress field Xpert Smt70
Endress field Xpert Smt70 Firmware
Endress field Xpert Smt77
Endress field Xpert Smt77 Firmware
Endress field Xpert Smt79
Endress field Xpert Smt79 Firmware
Endress fieldcare Sfe500 Package
CPEs cpe:2.3:a:endress:echo_curve_viewer:*:*:*:*:*:*:*:*
cpe:2.3:a:endress:fieldcare_sfe500_package:*:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt50:-:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt70:-:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt77:-:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt79:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt70_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt77_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt79_firmware:-:*:*:*:*:*:*:*
Vendors & Products Endress
Endress echo Curve Viewer
Endress field Xpert Smt50
Endress field Xpert Smt50 Firmware
Endress field Xpert Smt70
Endress field Xpert Smt70 Firmware
Endress field Xpert Smt77
Endress field Xpert Smt77 Firmware
Endress field Xpert Smt79
Endress field Xpert Smt79 Firmware
Endress fieldcare Sfe500 Package

Tue, 10 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Endress\+hauser
Endress\+hauser echo Curve Viewer Firmware
Endress\+hauser field Xpert Smt50 Firmware
Endress\+hauser field Xpert Smt70 Firmware
Endress\+hauser field Xpert Smt77 Firmware
Endress\+hauser field Xpert Smt79 Firmware
Endress\+hauser fieldcare Sfe500 Package Usb Firmware
Endress\+hauser fieldcare Sfe500 Package Web-package Firmware
CPEs cpe:2.3:o:endress\+hauser:echo_curve_viewer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt70_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt77_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt79_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:fieldcare_sfe500_package_usb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:fieldcare_sfe500_package_web-package_firmware:*:*:*:*:*:*:*:*
Vendors & Products Endress\+hauser
Endress\+hauser echo Curve Viewer Firmware
Endress\+hauser field Xpert Smt50 Firmware
Endress\+hauser field Xpert Smt70 Firmware
Endress\+hauser field Xpert Smt77 Firmware
Endress\+hauser field Xpert Smt79 Firmware
Endress\+hauser fieldcare Sfe500 Package Usb Firmware
Endress\+hauser fieldcare Sfe500 Package Web-package Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 08:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
Title Endress+Hauser: Multiple products are vulnerable to code injection
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Endress Echo Curve Viewer Field Xpert Smt50 Field Xpert Smt50 Firmware Field Xpert Smt70 Field Xpert Smt70 Firmware Field Xpert Smt77 Field Xpert Smt77 Firmware Field Xpert Smt79 Field Xpert Smt79 Firmware Fieldcare Sfe500 Package
Endress\+hauser Echo Curve Viewer Firmware Field Xpert Smt50 Firmware Field Xpert Smt70 Firmware Field Xpert Smt77 Firmware Field Xpert Smt79 Firmware Fieldcare Sfe500 Package Usb Firmware Fieldcare Sfe500 Package Web-package Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-09-10T18:46:17.099Z

Reserved: 2024-07-09T08:00:06.415Z

Link: CVE-2024-6596

cve-icon Vulnrichment

Updated: 2024-09-10T18:45:27.313Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-10T08:15:03.350

Modified: 2024-10-01T12:26:45.967

Link: CVE-2024-6596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses