CVE-2022-24314: High severity schneider-electric interactive graphical scada system vulnerability
Published Feb 9, 2022
·Updated
A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
Affected Software
2 affected components
Schneider-electric Interactive Graphical Scada System Data Server<=15.0.0.22020
Schneider Electric IGSS Data Server (IGSSdataServer.exe): v15.0.0.22020 and prior
Remediation
Event History
Feb 9, 2022
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2022-24314.
2
What is the severity level of CVE-2022-24314?
The severity level of CVE-2022-24314 is high.
3
What is the affected product of CVE-2022-24314?
The affected product of CVE-2022-24314 is the Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior).
4
What is the CWE ID of CVE-2022-24314?
The CWE ID of CVE-2022-24314 is CWE-125.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by repeatedly sending a specially crafted message, which could cause memory leaks potentially resulting in denial of service.