CVE-2021-22710: Buffer Overflow
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22710 vulnerability?
CVE-2021-22710 is a vulnerability that allows remote code execution in Schneider-electric Interactive Graphical Scada System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior versions when a malicious CGF (Configuration Group File) file is imported.
What is the severity of CVE-2021-22710?
CVE-2021-22710 has a severity rating of 7.8 (Critical).
How does CVE-2021-22710 affect Schneider-electric Interactive Graphical Scada System?
CVE-2021-22710 affects Schneider-electric Interactive Graphical Scada System (IGSS) Definition (Def.exe) versions up to 15.0.0.21041 by allowing remote code execution.
How can I fix CVE-2021-22710 vulnerability?
To fix CVE-2021-22710 vulnerability, it is recommended to update Interactive Graphical Scada System (IGSS) Definition (Def.exe) to version 15.0.0.21042 or later.
Where can I find more information about CVE-2021-22710 vulnerability?
More information about CVE-2021-22710 vulnerability can be found on the Schneider Electric website and in the SEVD-2021-068-01 advisory document.