CVE-2024-12399 MEDIUM

CVE-2024-12399

Vendor Schneider Electric
Product Pro-face GP-Pro EX
Weakness CWE-924
Published January 17, 2025
Last update September 9, 2025

CVSS base score

6.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.

Key dates

02Disclosure timeline

January 17, 2025 CVE published
September 9, 2025 Record updated