CVE-2016-2292

MEDIUM

Schneider-electric Proface Gp-pro EX Ex-ed - Out-of-Bounds Write

Title source: rule

Description

Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.

Scores

CVSS v3 6.5
EPSS 0.0163
EPSS Percentile 81.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-787
Status draft

Affected Products (4)

schneider-electric/proface_gp-pro_ex_ex-ed < 4.0.4
schneider-electric/proface_gp-pro_ex_pfxexedls < 4.0.4
schneider-electric/proface_gp-pro_ex_pfxexedv < 4.0.4
schneider-electric/proface_gp-pro_ex_pfxexgrpls < 4.0.4

Timeline

Published Apr 06, 2016
Tracked Since Feb 18, 2026