Vulnerability Description
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files or directories are removed from the filesystem.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Modicon M340 Firmware | All versions |
| Schneider-Electric | Modicon M340 | All versions |
| Schneider-Electric | Bmxnoe0100 Firmware | All versions |
| Schneider-Electric | Bmxnoe0100 | All versions |
| Schneider-Electric | Bmxnoe0110 Firmware | All versions |
| Schneider-Electric | Bmxnoe0110 | All versions |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-01&p_enDocVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-01&p_enDocVendor Advisory
FAQ
What is CVE-2024-5056?
CVE-2024-5056 is a vulnerability with a CVSS score of 6.5 (MEDIUM). CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the device firmware and prevent proper behavior of the webserver when specific files ...
How severe is CVE-2024-5056?
CVE-2024-5056 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5056?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Modicon M340 Firmware, Schneider-Electric Modicon M340, Schneider-Electric Bmxnoe0100 Firmware, Schneider-Electric Bmxnoe0100, Schneider-Electric Bmxnoe0110 Firmware.