Improper Memory Buffer Restriction in Schneider Electric SCADA System
CVE-2021-22709

7.8HIGH

Summary

A vulnerability exists in the Interactive Graphical SCADA System (IGSS) Definition, specifically in the Def.exe executable, allowing for improper access controls within memory operations. This can lead to severe risks, including potential data loss and the possibility of remote code execution when an attacker successfully imports a malicious Configuration Group File (CGF) into the system. Users of IGSS versions V15.0.0.21041 and earlier are encouraged to evaluate the implications of this vulnerability on their operational security.

Affected Version(s)

Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.