PT-2024-10225 · Schneider Electric · Schneider Electric Remoteconnect+1
Published
2024-12-17
·
Updated
2025-02-06
·
CVE-2024-12703
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
The affected software is Schneider Electric RemoteConnect and SCADAPack x70 Utilities, which have a deserialization of untrusted data issue. This could lead to loss of confidentiality, integrity, and potential remote code execution on a workstation when a non-admin authenticated user opens a malicious project file.
An exploit can be achieved if malicious project files are opened by non-admin authenticated users, posing risks to confidentiality and integrity.
More information about the issue can be found at https://t.co/qWVtHJNLEz, https://t.co/uXvPWJy6tj, and https://t.co/YXYqVha4iH.
#SchneiderElectric #RemoteConnect #SCADAPack #Deserialization #RemoteCodeExecution #Cybersecurity
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scadapack X70 Utilities
Schneider Electric Remoteconnect