Memory Corruption in VAMPSET Software by Schneider Electric
CVE-2017-7967
5.5MEDIUM
What is CVE-2017-7967?
The VAMPSET software from Schneider Electric is exposed to a memory corruption vulnerability due to handling corrupted vf2 files. When a malformed vf2 file is opened, the software may halt or fail to initiate, especially when it is launched in standalone mode without a connection to a protection relay. It's important to note that this vulnerability does not compromise the functionality of the connected protection relay and does not allow for exploitation over a network, as the software can be normally shut down through its standard closure protocol.
Affected Version(s)
VAMPSET All versions prior to 2.2.189