Improper Limitation of Pathname in Interactive Graphical SCADA System by Schneider Electric
CVE-2021-22804
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 February 2022
What is CVE-2021-22804?
A vulnerability exists in Schneider Electric's Interactive Graphical SCADA System due to improper validation of user-supplied data in network messages. This oversight could enable an attacker to access and read arbitrary files in the context of the user executing the system. The issue affects versions prior to V15.0.0.21243, posing a potential risk for unauthorized data disclosure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior) Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved