CVE-2020-7552: High severity interactive graphical scada system vulnerability
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability description of CVE-2020-7552?
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
What is the affected software of CVE-2020-7552?
Schneider-electric Interactive Graphical Scada System version 14.0.0.20247.
What is the severity of CVE-2020-7552?
The severity of CVE-2020-7552 is high, with a severity score of 7.8.
How can CVE-2020-7552 be exploited?
CVE-2020-7552 can be exploited by importing a malicious CGF file to IGSS Definition (Def.exe) version 14.0.0.20247, leading to remote code execution.
Is there a fix available for CVE-2020-7552?
Yes, please refer to the vendor's security advisory for the latest patches and updates to address CVE-2020-7552.