First published: Mon Jan 30 2023(Updated: )
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Interactive Graphical Scada System | <=15.0.0.22170 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32522 is a vulnerability that allows for a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages.
The severity of CVE-2022-32522 is critical with a CVSS score of 9.8.
The affected product is Schneider-electric Interactive Graphical Scada System (IGSS) Data Server version 15.0.0.22170.
CVE-2022-32522 can be exploited by an attacker sending specially crafted mathematically reduced data request messages.
Yes, a security notice with the fix is available at the following reference: [Schneider-electric Interactive Graphical Scada System Security Notice](https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification_V2.pdf).