CVE-2024-12476

HIGH

Web Designer <unknown - Info Disclosure/Remote Code Execution

Title source: llm
STIX 2.1

Description

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 45.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-611
Status published
Products (4)
Schneider Electric/Web Designer for BMENOC0311(C) All Versions
Schneider Electric/Web Designer for BMENOC0321(C) All Versions
Schneider Electric/Web Designer for BMXNOE0110(H) All versions
Schneider Electric/Web Designer for BMXNOR0200H All versions
Published Jan 17, 2025
Tracked Since Feb 18, 2026