CVE-2021-22753: High severity interactive graphical scada system vulnerability
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22753?
CVE-2021-22753 is a CWE-125: Out-of-bounds read vulnerability in IGSS Definition (Def.exe) V15.0.0.21140 and prior versions.
What is the impact of CVE-2021-22753?
The impact of CVE-2021-22753 is the loss of data or remote code execution due to missing length checks when a malicious WSP file is being parsed by IGSS Definition.
How can CVE-2021-22753 be exploited?
CVE-2021-22753 can be exploited by a malicious actor by providing a specially crafted WSP file to be parsed by IGSS Definition.
How severe is CVE-2021-22753?
CVE-2021-22753 has a severity score of 7.8, which is considered high.
How can I mitigate CVE-2021-22753?
To mitigate CVE-2021-22753, it is recommended to update IGSS Definition to a version that includes the fix for this vulnerability.