CVE-2024-11999: Schneider Electric Harmony Formerly Magelis HMIST6, HMISTM6, HMIG3U, HMIG3X, HMISTO7 Series With Ecostruxure Operator Terminal Expert Runtime

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.

Affected products

  • Schneider Electric Harmony Formerly Magelis HMIST6, HMISTM6, HMIG3U, HMIG3X, HMISTO7 Series With Ecostruxure Operator Terminal Expert Runtime: any version
  • Schneider Electric PFXST6000, PFXSTM6000, PFXSP5000, PFXGP4100 Series With Pro-Face Blue Runtime: any version

Published 2024-12-17. Last modified 2026-06-17.