VYPR

HMI

by Schneider Electric

CVEs (4)

  • CVE-2024-11999HigDec 17, 2024
    risk 0.57cvss 8.8epss 0.01

    CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.

  • CVE-2023-1049HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.01

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.

  • CVE-2026-9716HigJun 25, 2026
    risk 0.49cvss 7.5epss 0.00

    CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.

  • CVE-2024-12399HigJan 17, 2025
    risk 0.46cvss 7.1epss 0.00

    CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and availability of the HMI when attacker performs man in the middle attack by intercepting…