Security Advisory

CVE-2024-37038

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-06-12 16:51:55
Last updated 2024-08-02 03:43:50
Assigner schneider
CVSS score 7.5
State PUBLISHED

Description

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.