CVE-2024-12399: Schneider Electric Pro-Face Gp-Pro Ex
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.
Affected products
- Schneider Electric Pro-Face Gp-Pro Ex
- Schneider Electric Pro-Face Remote HMI: before v1.70.000 (fixed in v1.70.000)
Published 2025-01-17. Last modified 2026-06-17.