Missing Authentication Vulnerability in Interactive Graphical SCADA System by Schneider Electric
CVE-2021-22823
9.1CRITICAL
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 February 2022
What is CVE-2021-22823?
A vulnerability in Schneider Electric's Interactive Graphical SCADA System could allow an unauthorized user to delete arbitrary files by exploiting a lack of proper authentication for critical functions. This vulnerability arises due to insufficient validation of network messages, enabling potential misuse by malicious actors, particularly affecting users running the Data Collector (dc.exe) in versions V15.0.0.21320 and earlier.
Affected Version(s)
Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior) Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)