2024-03-18 17:03:19 +00:00
{
"id" : "CVE-2024-2229" ,
"sourceIdentifier" : "cybersecurity@se.com" ,
"published" : "2024-03-18T16:15:09.580" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T09:09:18.260" ,
2024-03-18 21:03:27 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-03-18 17:03:19 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "\nCWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code\nexecution when a malicious project file is loaded into the application by a valid user.\n\n"
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "CWE-502: Existe una vulnerabilidad de deserializaci\u00f3n de datos no confiables que podr\u00eda causar la ejecuci\u00f3n remota de c\u00f3digo cuando un usuario v\u00e1lido carga un archivo de proyecto malicioso en la aplicaci\u00f3n."
2024-03-18 17:03:19 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "cybersecurity@se.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
2024-03-18 17:03:19 +00:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-03-18 17:03:19 +00:00
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "cybersecurity@se.com" ,
2024-12-08 03:06:42 +00:00
"type" : "Secondary" ,
2024-03-18 17:03:19 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-502"
}
]
}
] ,
"references" : [
{
"url" : "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-072-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-072-02.pdf" ,
"source" : "cybersecurity@se.com"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-072-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-072-02.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-03-18 17:03:19 +00:00
}
]
}