First published: Fri Jan 28 2022(Updated: )
A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schneider Electric GUIcon Version 2.0 (Build 683.003) and prior
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Guicon | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22808 has a high severity rating due to the potential for arbitrary code execution.
To fix CVE-2021-22808, update Schneider Electric GUIcon to version 2.0 Build 683.004 or later.
CVE-2021-22808 is classified as a CWE-416 Use After Free vulnerability.
The affected product is Eurotherm by Schneider Electric GUIcon version 2.0 Build 683.003 and prior.
Exploiting CVE-2021-22808 could lead to arbitrary code execution on the affected system.