First published: Fri Jun 11 2021(Updated: )
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Interactive Graphical Scada System | <=15.0.0.21140 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22753 is a CWE-125: Out-of-bounds read vulnerability in IGSS Definition (Def.exe) V15.0.0.21140 and prior versions.
The impact of CVE-2021-22753 is the loss of data or remote code execution due to missing length checks when a malicious WSP file is being parsed by IGSS Definition.
CVE-2021-22753 can be exploited by a malicious actor by providing a specially crafted WSP file to be parsed by IGSS Definition.
CVE-2021-22753 has a severity score of 7.8, which is considered high.
To mitigate CVE-2021-22753, it is recommended to update IGSS Definition to a version that includes the fix for this vulnerability.