PT-2021-15190 · Schneider Electric · Igss

Published

2021-06-10

·

Updated

2021-06-15

·

CVE-2021-22752

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Schneider Electric IGSS versions prior to 15.0.0.21140
Description A vulnerability exists due to missing size checks when parsing a malicious WSP file, potentially resulting in loss of data or remote code execution.
Recommendations For versions prior to 15.0.0.21140, update to a version that includes the fix for this issue to prevent potential data loss or remote code execution.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22752
ZDI-21-673

Affected Products

Igss