CVE-2024-8422: Schneider Electric Zelio Soft 2
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.
Affected products
- Schneider Electric Zelio Soft 2: before 5.4.2.2 (fixed in 5.4.2.2)
Published 2024-10-08. Last modified 2026-06-17.