CVE-2024-10083 Details
Description
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
A denial-of-service vulnerability has been identified in the Uni-Telway driver, which is used in several Schneider Electric EcoStruxure products, including Control Expert, Process Expert, Process Expert for AVEVA System Platform, and OPC Factory Server. This vulnerability arises from improper input validation, allowing an authenticated user to disrupt engineering workstation operations by invoking a specific driver interface with crafted input.
Users of the affected products are advised to uninstall the Uni-Telway driver if it is not needed. For those who require the driver, Schneider Electric recommends using application control software such as McAfee Application and Change Control, and following workstation, network, and site-hardening guidelines. Version 16.2 of EcoStruxure Control Expert and version 3.63SP3 of OPC Factory Server do not include the Uni-Telway driver by default.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 13, 2025CISA-ADP
Assessed Feb 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-042-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-02.pdf | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Schneider Electric Uni-Telway driver | All versions |
CPE
Remediation
| |
| Schneider Electric EcoStruxure Control Expert | All versions |
CPE
Remediation
| |
| Schneider Electric EcoStruxure Process Expert | All versions |
CPE
Remediation
| |
| Schneider Electric EcoStruxure Process Expert for AVEVA System Platform | All versions |
CPE
Remediation
| |
| Schneider Electric OPC Factory Server | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | New CVE Received | [email protected] |
Volerion