CVE-2024-9005: Schneider Electric Ecostruxure Power Monitoring Expert
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.
Affected products
- Schneider Electric Ecostruxure Power Monitoring Expert: before 2022 (fixed in 2022)
- Schneider Electric Ecostruxure Power Monitoring Expert Pme: up to and including 2022
Published 2024-10-08. Last modified 2026-06-17.