CVE Database
/

CVE-2024-6596

Back to search

CVE-2024-6596

Published: Sep 10, 2024

Modified: Sep 10, 2024

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

VendorProductVersions

Endress+Hauser

Echo Curve Viewer

affected
0 - <= 5.2.2.6

Endress+Hauser

FieldCare SFE500 Package USB

affected
0 - <= V1.40.00.7448

Endress+Hauser

FieldCare SFE500 Package Web-Package

affected
0 - <= V1.40.00.7448

Endress+Hauser

Field Xpert SMT50

affected
0 - <= SMT50_Win10_LTSC_21H2_v1.07.00_RC02_03

Endress+Hauser

Field Xpert SMT70

affected
0 - <= SMT70_Win10_LTSC_21H2_v1.07.00_RC02_01

Endress+Hauser

Field Xpert SMT77

affected
0 - <= SMT77_Win10_SAC_22H2_v1.08.04_RC03_02

Endress+Hauser

Field Xpert SMT79

affected
0 - <= V1.08.02-1.8.8684.34292

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now