CVE-2024-12476
CVE-2024-12476
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.4EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
17 ene 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could
cause information disclosure, impacts workstation integrity and potential remote code execution on the
compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Schneider Electric · Web Designer for BMENOC0311(C)Schneider Electric · Web Designer for BMENOC0321(C)Schneider Electric · Web Designer for BMXNOE0110(H)Schneider Electric · Web Designer for BMXNOR0200H¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →