Lucene search

K
cveSchneiderCVE-2022-32525
HistoryJan 30, 2023 - 11:15 p.m.

CVE-2022-32525

2023-01-3023:15:10
CWE-120
schneider
web.nvd.nist.gov
25
cve-2022-32525
cwe-120
buffer overflow
igss data server
nvd
remote code execution

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.004

Percentile

75.3%

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)

Affected configurations

Nvd
Node
schneider-electricinteractive_graphical_scada_systemRange15.0.0.22170
VendorProductVersionCPE
schneider-electricinteractive_graphical_scada_system*cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Schneider Electric",
    "product": "IGSS Data Server (IGSSdataServer.exe)",
    "versions": [
      {
        "version": "All",
        "status": "affected",
        "lessThan": "V15.0.0.22170",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.004

Percentile

75.3%

Related for CVE-2022-32525