Security Advisory
CVE-2024-37038
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.