Vulnerability Description
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Endress | Echo Curve Viewer | < 6.0.0 |
| Endress | Fieldcare Sfe500 Package | < 1.40.1 |
| Endress | Field Xpert Smt79 Firmware | - |
| Endress | Field Xpert Smt79 | - |
| Endress | Field Xpert Smt77 Firmware | - |
| Endress | Field Xpert Smt77 | - |
| Endress | Field Xpert Smt70 Firmware | - |
| Endress | Field Xpert Smt70 | - |
| Endress | Field Xpert Smt50 Firmware | - |
| Endress | Field Xpert Smt50 | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en/advisories/VDE-2024-041Third Party Advisory
FAQ
What is CVE-2024-6596?
CVE-2024-6596 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
How severe is CVE-2024-6596?
CVE-2024-6596 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-6596?
Check the references section above for vendor advisories and patch information. Affected products include: Endress Echo Curve Viewer, Endress Fieldcare Sfe500 Package, Endress Field Xpert Smt79 Firmware, Endress Field Xpert Smt79, Endress Field Xpert Smt77 Firmware.