Improper Memory Buffer Restriction in Schneider Electric SCADA System
CVE-2021-22709
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 11 March 2021
Summary
A vulnerability exists in the Interactive Graphical SCADA System (IGSS) Definition, specifically in the Def.exe executable, allowing for improper access controls within memory operations. This can lead to severe risks, including potential data loss and the possibility of remote code execution when an attacker successfully imports a malicious Configuration Group File (CGF) into the system. Users of IGSS versions V15.0.0.21041 and earlier are encouraged to evaluate the implications of this vulnerability on their operational security.
Affected Version(s)
Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved