CVE-2024-5056
CVE-2024-5056
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Jun 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may
prevent user to update the device firmware and prevent proper behavior of the webserver when
specific files or directories are removed from the filesystem.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Affected products
Schneider Electric · Modicon M340Schneider Electric · Network module, Modicon M340, Ethernet TCP/IP BMXNOE0110Schneider Electric · Network module, Modicon M340, Modbus/TCP BMXNOE0100Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →