CVE-2020-7553
published 2020-11-19CVE-2020-7553: A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.33%
81.6th percentile
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | interactive_graphical_scada_system | <= 14.0.0.20247 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Interactive Graphical SCADA System (IGSS)
cisa_ics·2020-11-17·CVSS 7.8
[HIGH] Schneider Electric Interactive Graphical SCADA System (IGSS)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Interactive Graphical SCADA System (IGSS)
Last RevisedNovember 17, 2020
Alert CodeICSA-20-324-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low skill level to exploit
- Vendor: Schneider Electric
- Equipment: Interactive Graphical SCADA System (IGSS)
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Out-of-bounds Write, Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may result in remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The follo
GHSA
GHSA-7cwx-58fg-fmmx: A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def
ghsa_unreviewed·2022-05-24
CVE-2020-7553 [HIGH] CWE-787 GHSA-7cwx-58fg-fmmx: A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-11-19
Published