CVE-2021-22710
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- schneider-electric/interactive graphical scada system
- Source
- cybersecurity@se.com
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-068-01Patch, Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2021-068-01Broken Link, Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-068-01Patch, Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2021-068-01Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.