First published: Mon Jan 30 2023(Updated: )
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Interactive Graphical Scada System | <=15.0.0.22170 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-32524.
The severity of CVE-2022-32524 is critical, with a CVSS score of 9.8.
The CWE ID for this vulnerability is CWE-120.
This vulnerability occurs due to a buffer copy without checking the size of the input.
The affected product is Schneider-electric Interactive Graphical SCADA System (IGSS) Data Server version up to and including 15.0.0.22170.
This vulnerability can be exploited by an attacker sending specially crafted time reduced data messages, potentially leading to remote code execution.
Yes, there is a fix available. Please refer to the provided reference link for further information.
You can find more information about this vulnerability in the provided reference link.