CVE-2024-12399
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting the communication.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-924
- Published
- 2025-01-17
- Last modified
- 2026-03-13
Affected products
- Schneider Electric Pro-face GP-Pro EX
- Schneider Electric Pro-face Remote HMI
Weakness type
Related vulnerabilities
- CVE-2026-48106 — Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peer
- CVE-2026-68554 — Coturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requests
- CVE-2026-14681 — PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL
- CVE-2026-13584 — Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol
- CVE-2026-54891 — Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl
- CVE-2026-12576 — DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
- CVE-2019-25719 — Dräger Infinity M540 VG4.1.1 Spoofing and DoS via Network Message Handling
- CVE-2025-29628 — An issue in Gardyn 4 allows a remote attacker to obtain sensitive information and execute arbitrary...