cbcvebase.
CVE-2019-6824
published 2019-07-15

CVE-2019-6824: A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute…

PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.46%
90.3th percentile
A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.

Affected

2 ranges
VendorProductVersion rangeFixed in
proclimaproclima_all_versions_prior_to_version_8.0.0
schneider-electricproclima< 8.0.08.0.0

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2019-6824 is a buffer error (CWE-119) in Schneider Electric ProClima affecting all versions prior to 8.0.0, exploitable remotely with no authentication and no user interaction required (CVSS v3 9.8, AV:N/AC:L/PR:N/UI:N).
  • No known public exploits specifically target this vulnerability at time of advisory publication; monitor for anomalous remote code execution attempts against ProClima installations.
  • CVE-2019-6825 (a companion vulnerability in the same advisory) involves DLL hijacking — a malicious DLL with the same name as a resident DLL in the ProClima installation directory can execute arbitrary code; monitor for unexpected DLL loads from the ProClima install path.
  • ·All ProClima versions prior to 8.0.0 are affected; version 8.0.0 and newer are patched. Detections should target pre-8.0.0 deployments.
  • ·The vulnerability is network-exploitable with no privileges or user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), making internet-exposed ProClima instances at critical risk.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.