Improper Limitation of Pathname in Interactive Graphical SCADA System by Schneider Electric
CVE-2021-22804

7.5HIGH

Summary

A vulnerability exists in Schneider Electric's Interactive Graphical SCADA System due to improper validation of user-supplied data in network messages. This oversight could enable an attacker to access and read arbitrary files in the context of the user executing the system. The issue affects versions prior to V15.0.0.21243, posing a potential risk for unauthorized data disclosure.

Affected Version(s)

Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior) Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.