Missing Authentication Vulnerability in Interactive Graphical SCADA System by Schneider Electric
CVE-2021-22823
9.1CRITICAL
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 11 February 2022
Summary
A vulnerability in Schneider Electric's Interactive Graphical SCADA System could allow an unauthorized user to delete arbitrary files by exploiting a lack of proper authentication for critical functions. This vulnerability arises due to insufficient validation of network messages, enabling potential misuse by malicious actors, particularly affecting users running the Data Collector (dc.exe) in versions V15.0.0.21320 and earlier.
Affected Version(s)
Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior) Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved