CVE Database
/

CVE-2024-12399

Back to search

CVE-2024-12399

Published: Jan 17, 2025

Modified: Sep 9, 2025

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.

VendorProductVersions

Schneider Electric

Pro-face GP-Pro EX

affected
all version - < v5.00.100

Schneider Electric

Pro-face Remote HMI

affected
all versions - < v1.70.000

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now