CVE-2024-8422: Use After Free
Published Oct 8, 2024
·Updated
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.
Affected Software
1 affected component
Schneider-electric Zelio Soft 2<5.4.2.2
Event History
Oct 8, 2024
CVE Published
via MITRE·10:09 AM
Data Sourced
via MITRE·10:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8422?
CVE-2024-8422 has a high severity rating due to the potential for arbitrary code execution and denial of service.
2
How do I fix CVE-2024-8422?
To address CVE-2024-8422, users should update Schneider Electric Zelio Soft 2 to version 5.4.2.2 or later.
3
What is the impact of CVE-2024-8422?
The impact of CVE-2024-8422 can lead to arbitrary code execution, denial of service, and loss of confidentiality and integrity.
4
Which versions of Zelio Soft 2 are affected by CVE-2024-8422?
CVE-2024-8422 affects all versions of Schneider Electric Zelio Soft 2 prior to 5.4.2.2.
5
Can CVE-2024-8422 be exploited remotely?
Yes, CVE-2024-8422 can be exploited remotely when a user opens a malicious Zelio Soft 2 project file.