{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Sage 2400 avec un microgiciel ant\u00e9rieur \u00e0 C3414-500-S02K5_P9","product":{"name":"Sage 2400","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Network module, Modicon M340 et Ethernet TCP/IP BMXNOE0110 toutes versions","product":{"name":"Network module, Modicon M340 et Ethernet TCP/IP BMXNOE0110","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Sage 1450 avec un microgiciel ant\u00e9rieur \u00e0 C3414-500-S02K5_P9","product":{"name":"Sage 1450","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Sage 1430 avec un microgiciel ant\u00e9rieur \u00e0 C3414-500-S02K5_P9","product":{"name":"Sage 1430","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Sage 3030 Magnum avec un microgiciel ant\u00e9rieur \u00e0 C3414-500-S02K5_P9","product":{"name":"Sage 3030 Magnum","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Sage 1410 avec un microgiciel ant\u00e9rieur \u00e0 C3414-500-S02K5_P9","product":{"name":"Sage 1410","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"EVlink Home Smart versions 2.0.4.1.2_131 et 2.0.3.8.2_128 ant\u00e9rieures \u00e0 2.0.5.0.0_134","product":{"name":"EVlink Home Smart","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Network module, Modicon M340 et Ethernet TCP/IP BMXNOE0110","product":{"name":"Network module, Modicon M340 et Ethernet TCP/IP BMXNOE0110","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Modicon M340 toutes versions","product":{"name":"Modicon M340","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"PowerLogic P5 versions ant\u00e9rieures \u00e0 02.501.101","product":{"name":"PowerLogic P5","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Sage 4400 avec un microgiciel ant\u00e9rieur \u00e0 C3414-500-S02K5_P9","product":{"name":"Sage 4400","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"SpaceLogic AS-P et SpaceLogic AS-B versions ant\u00e9rieures \u00e0 6.0.1 ou versions 5.0.3 et 4.0.5 sans le dernier correctif de s\u00e9curit\u00e9","product":{"name":"N/A","vendor":{"name":"Schneider Electric","scada":true}}},{"description":"Network module, Modicon M340 et Modbus/TCP BMXNOE0100 toutes versions","product":{"name":"Network module, Modicon M340, Modbus/TCP BMXNOE0100","vendor":{"name":"Schneider Electric","scada":true}}}],"affected_systems_content":"","content":"## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des correctifs (cf. section Documentation).","cves":[{"name":"CVE-2024-5557","url":"https://www.cve.org/CVERecord?id=CVE-2024-5557"},{"name":"CVE-2024-37039","url":"https://www.cve.org/CVERecord?id=CVE-2024-37039"},{"name":"CVE-2024-5558","url":"https://www.cve.org/CVERecord?id=CVE-2024-5558"},{"name":"CVE-2024-5056","url":"https://www.cve.org/CVERecord?id=CVE-2024-5056"},{"name":"CVE-2024-37037","url":"https://www.cve.org/CVERecord?id=CVE-2024-37037"},{"name":"CVE-2024-5559","url":"https://www.cve.org/CVERecord?id=CVE-2024-5559"},{"name":"CVE-2024-5313","url":"https://www.cve.org/CVERecord?id=CVE-2024-5313"},{"name":"CVE-2024-37038","url":"https://www.cve.org/CVERecord?id=CVE-2024-37038"},{"name":"CVE-2024-37040","url":"https://www.cve.org/CVERecord?id=CVE-2024-37040"},{"name":"CVE-2024-5560","url":"https://www.cve.org/CVERecord?id=CVE-2024-5560"},{"name":"CVE-2024-37036","url":"https://www.cve.org/CVERecord?id=CVE-2024-37036"}],"links":[],"reference":"CERTFR-2024-AVI-0476","revisions":[{"description":"Version initiale","revision_date":"2024-06-11T00:00:00.000000"},{"description":"Ajout des identifiants CVE.","revision_date":"2024-06-14T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service \u00e0 distance"},{"description":"Atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"},{"description":"\u00c9l\u00e9vation de privil\u00e8ges"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits Schneider Electric. Certaines d'entre elles permettent \u00e0 un attaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.","title":"Multiples vuln\u00e9rabilit\u00e9s dans les produits Schneider Electric","vendor_advisories":[{"published_at":"2024-06-11","title":"Bulletin de s\u00e9curit\u00e9 Schneider Electric SEVD-2024-163-02","url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-02.pdf"},{"published_at":"2024-06-11","title":"Bulletin de s\u00e9curit\u00e9 Schneider Electric SEVD-2024-163-01","url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-01.pdf"},{"published_at":"2024-06-11","title":"Bulletin de s\u00e9curit\u00e9 Schneider Electric SEVD-2024-163-03","url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-03.pdf"},{"published_at":"2024-06-11","title":"Bulletin de s\u00e9curit\u00e9 Schneider Electric SEVD-2024-163-05","url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-05.pdf"},{"published_at":"2024-06-11","title":"Bulletin de s\u00e9curit\u00e9 Schneider Electric SEVD-2024-163-04","url":"https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-163-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-163-04.pdf"}]}
