CVE-2024-10083

MEDIUM

Schneider Electric Uni-Telway driver - Authenticated Denial of Service via Crafted Input

Title source: llm
STIX 2.1

Description

CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (5)
Schneider Electric/Uni-Telway driver All versions
Schneider Electric/Uni-Telway driver used in EcoStruxure Control Expert All versions
Schneider Electric/Uni-Telway driver used in EcoStruxure Process Expert All Versions
Schneider Electric/Uni-Telway driver used in EcoStruxure Process Expert for AVEVA System Platform All Versions
Schneider Electric/Uni-Telway driver used in OPC Factory Server All Versions
Published Feb 13, 2025
Tracked Since Feb 18, 2026