An unspecified ActiveX control in Schneider Electric SoMachine HVAC Programming Software for M171/M172 Controllers before 2.1.0 allows remote attackers to execute arbitrary code via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.
2016-07-15T16:59:10.347
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 7.3 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Hardware | schneider-electric | m171 | - | No |
| Hardware | schneider-electric | m172 | - | No |
| Operating System | schneider-electric | somachine_hvac_firmware | ≤ 2.0.2 | Yes |