Memory Corruption in VAMPSET Software by Schneider Electric
CVE-2017-7967

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 May 2017

What is CVE-2017-7967?

The VAMPSET software from Schneider Electric is exposed to a memory corruption vulnerability due to handling corrupted vf2 files. When a malformed vf2 file is opened, the software may halt or fail to initiate, especially when it is launched in standalone mode without a connection to a protection relay. It's important to note that this vulnerability does not compromise the functionality of the connected protection relay and does not allow for exploitation over a network, as the software can be normally shut down through its standard closure protocol.

Affected Version(s)

VAMPSET All versions prior to 2.2.189

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.