An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
History

Tue, 01 Oct 2024 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Endress
Endress echo Curve Viewer
Endress field Xpert Smt50
Endress field Xpert Smt50 Firmware
Endress field Xpert Smt70
Endress field Xpert Smt70 Firmware
Endress field Xpert Smt77
Endress field Xpert Smt77 Firmware
Endress field Xpert Smt79
Endress field Xpert Smt79 Firmware
Endress fieldcare Sfe500 Package
CPEs cpe:2.3:a:endress:echo_curve_viewer:*:*:*:*:*:*:*:*
cpe:2.3:a:endress:fieldcare_sfe500_package:*:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt50:-:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt70:-:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt77:-:*:*:*:*:*:*:*
cpe:2.3:h:endress:field_xpert_smt79:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt70_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt77_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:endress:field_xpert_smt79_firmware:-:*:*:*:*:*:*:*
Vendors & Products Endress
Endress echo Curve Viewer
Endress field Xpert Smt50
Endress field Xpert Smt50 Firmware
Endress field Xpert Smt70
Endress field Xpert Smt70 Firmware
Endress field Xpert Smt77
Endress field Xpert Smt77 Firmware
Endress field Xpert Smt79
Endress field Xpert Smt79 Firmware
Endress fieldcare Sfe500 Package

Tue, 10 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Endress\+hauser
Endress\+hauser echo Curve Viewer Firmware
Endress\+hauser field Xpert Smt50 Firmware
Endress\+hauser field Xpert Smt70 Firmware
Endress\+hauser field Xpert Smt77 Firmware
Endress\+hauser field Xpert Smt79 Firmware
Endress\+hauser fieldcare Sfe500 Package Usb Firmware
Endress\+hauser fieldcare Sfe500 Package Web-package Firmware
CPEs cpe:2.3:o:endress\+hauser:echo_curve_viewer_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt70_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt77_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:field_xpert_smt79_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:fieldcare_sfe500_package_usb_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:endress\+hauser:fieldcare_sfe500_package_web-package_firmware:*:*:*:*:*:*:*:*
Vendors & Products Endress\+hauser
Endress\+hauser echo Curve Viewer Firmware
Endress\+hauser field Xpert Smt50 Firmware
Endress\+hauser field Xpert Smt70 Firmware
Endress\+hauser field Xpert Smt77 Firmware
Endress\+hauser field Xpert Smt79 Firmware
Endress\+hauser fieldcare Sfe500 Package Usb Firmware
Endress\+hauser fieldcare Sfe500 Package Web-package Firmware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 08:15:00 +0000

Type Values Removed Values Added
Description An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
Title Endress+Hauser: Multiple products are vulnerable to code injection
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2024-09-10T08:01:26.429Z

Updated: 2024-09-10T18:46:17.099Z

Reserved: 2024-07-09T08:00:06.415Z

Link: CVE-2024-6596

cve-icon Vulnrichment

Updated: 2024-09-10T18:45:27.313Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-10T08:15:03.350

Modified: 2024-10-01T12:26:45.967

Link: CVE-2024-6596

cve-icon Redhat

No data.