# CVE-2024-12399

## Summary

- **CVE ID:** CVE-2024-12399
- **Severity:** MEDIUM
- **CVSS Score:** 7.1 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-924
- **Published:** Jan 17, 2025
- **Last Modified:** Mar 13, 2026

## Description

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability
exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs
man in the middle attack by intercepting the communication.

## Affected Products

- Schneider Electric — Pro-face GP-Pro EX (all version)
- Schneider Electric — Pro-face Remote HMI (all versions)

## References

- [CNA](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-014-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-014-02.pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._