Improper Memory Buffer Restriction in Schneider Electric SCADA System
CVE-2021-22709
7.8HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 March 2021
What is CVE-2021-22709?
A vulnerability exists in the Interactive Graphical SCADA System (IGSS) Definition, specifically in the Def.exe executable, allowing for improper access controls within memory operations. This can lead to severe risks, including potential data loss and the possibility of remote code execution when an attacker successfully imports a malicious Configuration Group File (CGF) into the system. Users of IGSS versions V15.0.0.21041 and earlier are encouraged to evaluate the implications of this vulnerability on their operational security.
Affected Version(s)
Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior