CVE-2021-22709: Buffer Overflow
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22709?
CVE-2021-22709 is a vulnerability in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution.
How severe is CVE-2021-22709?
CVE-2021-22709 has a severity score of 7.8, which is classified as critical.
How does CVE-2021-22709 impact Schneider-electric Interactive Graphical Scada System?
CVE-2021-22709 can result in loss of data or remote code execution in Schneider-electric Interactive Graphical Scada System (version V15.0.0.21041 and prior).
How can I fix CVE-2021-22709?
To fix CVE-2021-22709, it is recommended to update Interactive Graphical SCADA System (IGSS) Definition (Def.exe) to version 15.0.0.21041 or later.
Where can I find more information about CVE-2021-22709?
You can find more information about CVE-2021-22709 in the following references: [SEVD-2021-068-01](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-068-01) and [SEVD-2021-068-01](https://www.se.com/ww/en/download/document/SEVD-2021-068-01).