CVE-2021-22759: Use After Free
Published Jun 11, 2021
·Updated
A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to use of unchecked input data, when a malicious CGF file is imported to IGSS Definition.
Affected Software
1 affected component
Schneider-electric Interactive Graphical Scada System<=15.0.0.21140
Event History
Jun 11, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-22759.
2
What is the severity level of CVE-2021-22759?
The severity level of CVE-2021-22759 is high with a score of 7.8.
3
What is the affected software version for CVE-2021-22759?
The affected software version for CVE-2021-22759 is IGSS Definition (Def.exe) V15.0.0.21140 and prior.
4
What is CWE-416?
CWE-416 refers to a use after free vulnerability.
5
What is the potential impact of CVE-2021-22759?
The potential impact of CVE-2021-22759 includes loss of data or remote code execution when a malicious CGF file is imported to IGSS Definition.