CVE-2016-4529
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/07/2016
Last modified:
12/04/2025
Description
An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers before 2.1.0 allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.
Impact
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:h:schneider-electric:m171:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:m172:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:somachine_hvac_firmware:*:*:*:*:*:*:*:* | 2.0.2 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-161-01
- http://www.securityfocus.com/bid/91778
- http://www.zerodayinitiative.com/advisories/ZDI-16-440
- https://ics-cert.us-cert.gov/advisories/ICSA-16-196-03
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2016-161-01
- http://www.securityfocus.com/bid/91778
- http://www.zerodayinitiative.com/advisories/ZDI-16-440
- https://ics-cert.us-cert.gov/advisories/ICSA-16-196-03



