PT-2024-10225 · Schneider Electric · Schneider Electric Remoteconnect+1

Published

2024-12-17

·

Updated

2025-02-06

·

CVE-2024-12703

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
The affected software is Schneider Electric RemoteConnect and SCADAPack x70 Utilities, which have a deserialization of untrusted data issue. This could lead to loss of confidentiality, integrity, and potential remote code execution on a workstation when a non-admin authenticated user opens a malicious project file. An exploit can be achieved if malicious project files are opened by non-admin authenticated users, posing risks to confidentiality and integrity. More information about the issue can be found at https://t.co/qWVtHJNLEz, https://t.co/uXvPWJy6tj, and https://t.co/YXYqVha4iH. #SchneiderElectric #RemoteConnect #SCADAPack #Deserialization #RemoteCodeExecution #Cybersecurity

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-00560
CVE-2024-12703

Affected Products

Scadapack X70 Utilities
Schneider Electric Remoteconnect