CVE-2024-9005
published 2024-10-08CVE-2024-9005: CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is…
PriorityP341high7.3CVSS 4.0
AVNACHATNPRLUIAVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.34%
26.4th percentile
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized data is posted to the web server.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider_electric | ecostruxure_power_monitoring_expert | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h25j-66v8-m35v: CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized
ghsa_unreviewed·2024-10-08
CVE-2024-9005 [HIGH] CWE-502 GHSA-h25j-66v8-m35v: CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized
CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be
remotely executed on the server when unsafely deserialized data is posted to the web server.
CISA ICS
Schneider Electric EcoStruxure Power Monitoring Expert (PME) (Update B)
cisa_ics·2025-05-20·CVSS 7.3
[HIGH] Schneider Electric EcoStruxure Power Monitoring Expert (PME) (Update B)
ICS Advisory
##
Schneider Electric EcoStruxure Power Monitoring Expert (PME) (Update B)
Last RevisedMay 20, 2025
Alert CodeICSA-25-037-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 7.3
- ATTENTION: Exploitable remotely
- Vendor: Schneider Electric
- Equipment: EcoStruxure Power Monitoring Expert (PME)
- Vulnerability: Deserialization of Untrusted Data
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to remotely execute code.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneider Electric reports the following products are affected:
- Schneider Electric EcoStruxure Power Monitoring Expert (PME): 2022
- Schneider Elect
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-08
Published