First published: Tue Oct 08 2024(Updated: )
CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens a malicious Zelio Soft 2 project file.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Zelio Soft 2 | <5.4.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8422 has a high severity rating due to the potential for arbitrary code execution and denial of service.
To address CVE-2024-8422, users should update Schneider Electric Zelio Soft 2 to version 5.4.2.2 or later.
The impact of CVE-2024-8422 can lead to arbitrary code execution, denial of service, and loss of confidentiality and integrity.
CVE-2024-8422 affects all versions of Schneider Electric Zelio Soft 2 prior to 5.4.2.2.
Yes, CVE-2024-8422 can be exploited remotely when a user opens a malicious Zelio Soft 2 project file.