CVE-2024-11999: Schneider Electric Harmony Formerly Magelis HMIST6, HMISTM6, HMIG3U, HMIG3X, HMISTO7 Series With Ecostruxure Operator Terminal Expert Runtime
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.
Affected products
- Schneider Electric Harmony Formerly Magelis HMIST6, HMISTM6, HMIG3U, HMIG3X, HMISTO7 Series With Ecostruxure Operator Terminal Expert Runtime: any version
- Schneider Electric PFXST6000, PFXSTM6000, PFXSP5000, PFXGP4100 Series With Pro-Face Blue Runtime: any version
Published 2024-12-17. Last modified 2026-06-17.