CVE-2024-8884

CRITICAL

Schneider Electric System Monitor in Harmony Industrial PC & Pro-face PS5000 - Sensitive Info Exposure via HTTP

Title source: llm
STIX 2.1

Description

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (2)
Schneider Electric/System Monitor application in Harmony Industrial PC HMIBMO/HMIBMI/HMIPSO/HMIBMP/HMIBMU/HMIPSP/HMIPEP series All versions
Schneider Electric/System Monitor application in Pro-face Industrial PC PS5000 series All versions
Published Oct 08, 2024
Tracked Since Feb 18, 2026