CVE-2024-12476: Schneider Electric Web Designer For BMENOC0311C
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.
Affected products
- Schneider Electric Web Designer For BMENOC0311C: any version
- Schneider Electric Web Designer For BMENOC0321C: any version
- Schneider Electric Web Designer For BMXNOE0110H: any version
- Schneider Electric Web Designer For BMXNOR0200H: any version
Published 2025-01-17. Last modified 2026-06-17.