CVE-2019-6823: Schneider Electric Proclima

Critical severity, CVSS 9.8. EPSS: 5% chance of exploitation in the next 30 days.

A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.

Affected products

Published 2019-07-15. Last modified 2026-06-17.