CVE-2024-8306
published 2024-09-11CVE-2024-8306: CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.1th percentile
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity and availability of the workstation when non-admin
authenticated user tries to perform privilege escalation by tampering with the binaries.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | vijeo_designer | < 6.3 | 6.3 |
| schneider-electric | vijeo_designer | — | — |
| schneider_electric | vijeo_designer | — | — |
| schneider_electric | vijeo_designer_embedded_in_ecostruxure_machine_expert | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9c5-cgr2-rx6v: CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity and availability
ghsa_unreviewed·2024-09-11
CVE-2024-8306 [HIGH] CWE-269 GHSA-q9c5-cgr2-rx6v: CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity and availability
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity and availability of the workstation when non-admin
authenticated user tries to perform privilege escalation by tampering with the binaries.
CISA ICS
Schneider Electric Vijeo Designer and EcoStruxure Machine Expert (Update A)
cisa_ics·2025-07-22·CVSS 7.8
[HIGH] Schneider Electric Vijeo Designer and EcoStruxure Machine Expert (Update A)
ICS Advisory
##
Schneider Electric Vijeo Designer and EcoStruxure Machine Expert (Update A)
Last RevisedJuly 22, 2025
Alert CodeICSA-25-014-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low Attack Complexity
- Vendor: Schneider Electric
- Equipment: Vijeo Designer
- Vulnerability: Improper Privilege Management
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a non-admin authenticated user to perform privilege escalation by tampering with the binaries.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneider Electric reports that the following products are affected:
- Vijeo Designer: All versions prior to 6.3 SP1
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-09-11
Published