CVE-2021-22775
HIGHGP-Pro EX <V4.09.250 - Code Injection
Title source: llmDescription
A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevated privileges when installing the software.
Scores
CVSS v3
7.8
EPSS
0.0007
EPSS Percentile
20.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
schneider-electric/gp-pro_ex
< 4.09.250
Timeline
Published
Sep 02, 2021
Tracked Since
Feb 18, 2026