Vulnerability Details CVE-2021-22751
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.0%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2021-22751
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:10.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:12.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:13.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:13.0.0.19140
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0.0.19120
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0.0.20009
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0.0.20247
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:9.0