CVE-2024-10575: Schneider Electric Ecostruxure It Gateway
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
Affected products
- Schneider Electric Ecostruxure It Gateway: version 1.21.0.6 only; version 1.22.0.3 only; version 1.22.1.5 only; version 1.23.0.4 only
Published 2024-11-13. Last modified 2026-06-17.