CVE-2021-22752
published 2021-06-11CVE-2021-22752: A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.17%
63.8th percentile
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | interactive_graphical_scada_system | <= 15.0.0.21140 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5579-33mm-x832: A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def
ghsa_unreviewed·2022-05-24
CVE-2021-22752 [HIGH] CWE-787 GHSA-5579-33mm-x832: A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.
CISA ICS
Schneider Electric IGSS
cisa_ics·2021-06-08·CVSS 7.8
[HIGH] Schneider Electric IGSS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric IGSS
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Schneider Electric
- Equipment: IGSS (Interactive Graphical SCADA System)
- Vulnerabilities: Out-of-bounds Write, Out-of-bounds Read, Access of Uninitialized Pointer, Use After Free, Release of Invalid Pointer or Reference, Improper Limitation of a Pathname to a Restricted Directory
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may result in remote code execution, which could result in an atta
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-11
Published