PatchSiren cyber security CVE debrief
CVE-2024-37036 Schneider Electric CVE debrief
CVE-2024-37036 is a critical Schneider Electric Sage vulnerability that CISA and Schneider Electric describe as a CWE-787 out-of-bounds write. Under particular configuration parameters, a malformed POST request can lead to authentication bypass. The affected products are Sage 1410, 1430, 1450, 2400, 3030 Magnum, and 4400 versions C3414-500-S02K5_P8 and earlier. Schneider Electric provides firmware C3414-500-S02K5_P9 as the fix, and the CISA advisory was updated on 2024-07-09 to add a direct remediation link.
- Vendor
- Schneider Electric
- Product
- Sage 1410
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-11
- Original CVE updated
- 2024-07-09
- Advisory published
- 2024-06-11
- Advisory updated
- 2024-07-09
Who should care
Operators and asset owners running Schneider Electric Sage 1410, 1430, 1450, 2400, 3030 Magnum, or 4400 devices, plus OT/ICS teams responsible for patching and access control in industrial environments.
Technical summary
The advisory describes a CWE-787 out-of-bounds write in Sage RTU firmware. When specific configuration parameters are set, sending a malformed POST request can result in authentication bypass. The supplied data assigns CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating network-reachable, no-privilege, high-impact exposure if the vulnerable configuration is present.
Defensive priority
Immediate
Recommended defensive actions
- Upgrade affected Sage devices to firmware version C3414-500-S02K5_P9 as provided by Schneider Electric.
- Verify whether any deployed Sage 1410/1430/1450/2400/3030 Magnum/4400 units are at C3414-500-S02K5_P8 or earlier and prioritize those systems.
- Confirm the specific configuration parameters referenced in the advisory are not present on exposed systems until remediation is complete.
- Use Schneider Electric and CISA advisory guidance to plan deployment and validation, and record the remediation status for each affected asset.
- Apply ICS defense-in-depth practices such as limiting management access and segmenting OT assets while remediation is underway.
Evidence notes
Primary evidence comes from CISA CSAF advisory ICSA-25-107-02 and Schneider Electric notice SEVD-2024-163-05. The advisory lists six affected Sage product lines, states the vulnerable versions are C3414-500-S02K5_P8 and earlier, and identifies firmware C3414-500-S02K5_P9 as the remediation. The revision history shows the advisory was originally released on 2024-06-11 and updated on 2024-07-09 to add a direct remediation link.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-37036 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-37036
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-37036 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-37036
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-107-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/us/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-107-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.