CVE-2024-12476: Schneider Electric Web Designer For BMENOC0311C

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.

Affected products

Published 2025-01-17. Last modified 2026-06-17.