PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-37036 Schneider Electric CVE debrief

CVE-2024-37036 is a critical Schneider Electric Sage vulnerability that CISA and Schneider Electric describe as a CWE-787 out-of-bounds write. Under particular configuration parameters, a malformed POST request can lead to authentication bypass. The affected products are Sage 1410, 1430, 1450, 2400, 3030 Magnum, and 4400 versions C3414-500-S02K5_P8 and earlier. Schneider Electric provides firmware C3414-500-S02K5_P9 as the fix, and the CISA advisory was updated on 2024-07-09 to add a direct remediation link.

Vendor
Schneider Electric
Product
Sage 1410
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-07-09
Advisory published
2024-06-11
Advisory updated
2024-07-09

Who should care

Operators and asset owners running Schneider Electric Sage 1410, 1430, 1450, 2400, 3030 Magnum, or 4400 devices, plus OT/ICS teams responsible for patching and access control in industrial environments.

Technical summary

The advisory describes a CWE-787 out-of-bounds write in Sage RTU firmware. When specific configuration parameters are set, sending a malformed POST request can result in authentication bypass. The supplied data assigns CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating network-reachable, no-privilege, high-impact exposure if the vulnerable configuration is present.

Defensive priority

Immediate

Recommended defensive actions

  • Upgrade affected Sage devices to firmware version C3414-500-S02K5_P9 as provided by Schneider Electric.
  • Verify whether any deployed Sage 1410/1430/1450/2400/3030 Magnum/4400 units are at C3414-500-S02K5_P8 or earlier and prioritize those systems.
  • Confirm the specific configuration parameters referenced in the advisory are not present on exposed systems until remediation is complete.
  • Use Schneider Electric and CISA advisory guidance to plan deployment and validation, and record the remediation status for each affected asset.
  • Apply ICS defense-in-depth practices such as limiting management access and segmenting OT assets while remediation is underway.

Evidence notes

Primary evidence comes from CISA CSAF advisory ICSA-25-107-02 and Schneider Electric notice SEVD-2024-163-05. The advisory lists six affected Sage product lines, states the vulnerable versions are C3414-500-S02K5_P8 and earlier, and identifies firmware C3414-500-S02K5_P9 as the remediation. The revision history shows the advisory was originally released on 2024-06-11 and updated on 2024-07-09 to add a direct remediation link.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-37036 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-37036

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-37036 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-37036

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-107-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.se.com/us/en/download/document/7EN52-0390/

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.