CVE-2021-22751: Input Validation
Published Jun 11, 2021
·Updated
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.
Affected Software
1 affected component
Schneider-electric Interactive Graphical Scada System<=15.0.0.21140
Event History
Jun 11, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22751.
2
What is the severity level of CVE-2021-22751?
The severity level of CVE-2021-22751 is high (7.8).
3
What is the affected software by CVE-2021-22751?
The affected software by CVE-2021-22751 is Schneider-electric Interactive Graphical Scada System V15.0.0.21140 and prior versions.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-787.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by importing a malicious CGF (Configuration Group File) file to IGSS Definition.