{"api_version":"1","generated_at":"2026-07-23T10:25:00+00:00","cve":"CVE-2019-6824","urls":{"html":"https://cve.report/CVE-2019-6824","api":"https://cve.report/api/cve/CVE-2019-6824.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-6824","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-6824"},"summary":{"title":"CVE-2019-6824","description":"A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.","state":"PUBLIC","assigner":"cybersecurity@schneider-electric.com","published_at":"2019-07-15 21:15:00","updated_at":"2022-10-14 03:04:00"},"problem_types":["CWE-119"],"metrics":[],"references":[{"url":"https://www.schneider-electric.com/en/download/document/SEVD-2019-162-01/","name":"https://www.schneider-electric.com/en/download/document/SEVD-2019-162-01/","refsource":"MISC","tags":["Vendor Advisory"],"title":"Security Notification - ProClima (V1.1) | Schneider Electric","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-6824","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6824","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"6824","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"schneider-electric","cpe5":"proclima","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6824","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"schneider-electric","cpe5":"proclima","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-6824","ASSIGNER":"cybersecurity@schneider-electric.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"ProClima","product":{"product_data":[{"product_name":"ProClima all versions prior to version 8.0.0","version":{"version_data":[{"version_value":"ProClima all versions prior to version 8.0.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-119: Buffer Errors"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.schneider-electric.com/en/download/document/SEVD-2019-162-01/","url":"https://www.schneider-electric.com/en/download/document/SEVD-2019-162-01/"}]},"description":{"description_data":[{"lang":"eng","value":"A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0."}]}},"nvd":{"publishedDate":"2019-07-15 21:15:00","lastModifiedDate":"2022-10-14 03:04:00","problem_types":["CWE-119"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":10},"severity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:schneider-electric:proclima:*:*:*:*:*:*:*:*","versionEndExcluding":"8.0.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"6824","Ordinal":"144558","Title":"CVE-2019-6824","CVE":"CVE-2019-6824","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"6824","Ordinal":"1","NoteData":"A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"6824","Ordinal":"2","NoteData":"2019-07-15","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"6824","Ordinal":"3","NoteData":"2019-07-15","Type":"Other","Title":"Modified"}]}}}