CVE-2016-4529 | Schneider Electric SoMachine HVAC up to 2.0 on M171/M172 ActiveX Control INTERFACESAFE_FOR_UNTRUSTED_CALLER privileges management (ID 370086 / BID-91778)

A vulnerability was found in Schneider Electric SoMachine HVAC up to 2.0 on M171/M172. It has been classified as critical. This affects an unknown part of the component ActiveX Control. The manipulation of the argument INTERFACESAFE_FOR_UNTRUSTED_CALLER leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2016-4529. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.