CVE-2024-12476
HIGHWeb Designer <unknown - Info Disclosure/Remote Code Execution
Title source: llmDescription
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.
Scores
CVSS v3
7.8
EPSS
0.0023
EPSS Percentile
45.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-611
Status
published
Products (4)
Schneider Electric/Web Designer for BMENOC0311(C)
All Versions
Schneider Electric/Web Designer for BMENOC0321(C)
All Versions
Schneider Electric/Web Designer for BMXNOE0110(H)
All versions
Schneider Electric/Web Designer for BMXNOR0200H
All versions
Published
Jan 17, 2025
Tracked Since
Feb 18, 2026