First published: Fri Jun 11 2021(Updated: )
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Interactive Graphical Scada System | <=15.0.0.21140 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this out-of-bounds write vulnerability is CVE-2021-22754.
The severity rating of CVE-2021-22754 is 7.8 (High).
The affected software version for CVE-2021-22754 is IGSS Definition (Def.exe) V15.0.0.21140 and prior.
This vulnerability can be exploited by importing a malicious CGF file to IGSS Definition.
Currently, no specific fix information is available. It is recommended to follow the vendor's advisory and apply any updates or patches as they become available.