Improper Limitation of Pathname in Interactive Graphical SCADA System by Schneider Electric
CVE-2021-22804
7.5HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 February 2022
What is CVE-2021-22804?
A vulnerability exists in Schneider Electric's Interactive Graphical SCADA System due to improper validation of user-supplied data in network messages. This oversight could enable an attacker to access and read arbitrary files in the context of the user executing the system. The issue affects versions prior to V15.0.0.21243, posing a potential risk for unauthorized data disclosure.
Affected Version(s)
Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior) Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)