Improper Input Validation Vulnerability in Pro-Face GP-Pro EX by Schneider Electric
CVE-2018-7832
8.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 24 December 2018
Summary
An improper input validation vulnerability exists in Pro-Face GP-Pro EX versions up to v4.08. This flaw could allow an attacker to execute arbitrary code when the application is launched, potentially compromising the system. It's essential for users of these versions to implement protective measures to mitigate the risk posed by this vulnerability.
Affected Version(s)
Pro-Face GP-Pro EX v4.08 and previous Pro-Face GP-Pro EX v4.08 and previous versions
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved