Schneider-electric
Schneider-electric Interactive Graphical Scada System: vulnerabilidades y CVE
Schneider-electric Interactive Graphical Scada System tiene 43 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE43
Últimos 12 meses0
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-4516 | Alta (7.8) | 0.18% | — | 14 sept 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the… |
| CVE-2022-2329 | Crítica (9.8) | 2.1% | — | 1 feb 2023 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially… |
| CVE-2022-24324 | Crítica (9.8) | 1.2% | — | 1 feb 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message.… |
| CVE-2022-32529 | Crítica (9.8) | 1.3% | — | 30 ene 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data… |
| CVE-2022-32528 | Crítica (9.1) | 0.47% | — | 30 ene 2023 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGSS project report directory, potentially leading to a denial-of-service… |
| CVE-2022-32527 | Crítica (9.8) | 1.3% | — | 30 ene 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm… |
| CVE-2022-32526 | Crítica (9.8) | 1.3% | — | 30 ene 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting… |
| CVE-2022-32525 | Crítica (9.8) | 1.3% | — | 30 ene 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data… |
| CVE-2022-32524 | Crítica (9.8) | 1.3% | — | 30 ene 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time… |
| CVE-2022-32523 | Crítica (9.8) | 1.3% | — | 30 ene 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online… |
| CVE-2022-32522 | Crítica (9.8) | 1.1% | — | 30 ene 2023 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted… |
| CVE-2021-22762 | Alta (7.8) | 1.4% | — | 11 jun 2021 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file… |
| CVE-2021-22761 | Alta (7.8) | 0.66% | — | 11 jun 2021 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code… |
| CVE-2021-22760 | Alta (7.8) | 1.2% | — | 11 jun 2021 | A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of… |
| CVE-2021-22759 | Alta (7.8) | 1.2% | — | 11 jun 2021 | A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to use of unchecked input data, when a malicious CGF file… |
| CVE-2021-22758 | Alta (7.8) | 1.2% | — | 11 jun 2021 | A CWE-824: Access of uninitialized pointer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack validation of user-supplied… |
| CVE-2021-22757 | Alta (7.8) | 1.3% | — | 11 jun 2021 | A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on… |
| CVE-2021-22756 | Alta (7.8) | 1.3% | — | 11 jun 2021 | A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of user-supplied data… |
| CVE-2021-22755 | Alta (7.8) | 1.3% | — | 11 jun 2021 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on… |
| CVE-2021-22754 | Alta (7.8) | 1.2% | — | 11 jun 2021 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data,… |
| CVE-2021-22753 | Alta (7.8) | 1.2% | — | 11 jun 2021 | A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file… |
| CVE-2021-22752 | Alta (7.8) | 1.2% | — | 11 jun 2021 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP… |
| CVE-2021-22751 | Alta (7.8) | 0.85% | — | 11 jun 2021 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when… |
| CVE-2021-22750 | Alta (7.8) | 1.2% | — | 11 jun 2021 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file… |
| CVE-2021-22712 | Alta (7.8) | 0.93% | — | 11 mar 2021 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in… |
| CVE-2021-22711 | Alta (7.8) | 0.88% | — | 11 mar 2021 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in… |
| CVE-2021-22710 | Alta (7.8) | 2.2% | — | 11 mar 2021 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote… |
| CVE-2021-22709 | Alta (7.8) | 2.2% | — | 11 mar 2021 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in… |
| CVE-2020-7558 | Alta (7.8) | 2.5% | — | 19 nov 2020 | A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS… |
| CVE-2020-7557 | Alta (7.8) | 2.5% | — | 19 nov 2020 | A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS… |
Otros productos de Schneider-electric
Struxureware Data Center Expert · 49Modicon M580 Firmware · 41Modicon M340 Firmware · 39Modicon M340 Bmxp342020 Firmware · 32Modicon M340 Bmxp3420302 Firmware · 28Modicon M340 Bmxp341000 Firmware · 27Ecostruxure Control Expert · 26Modicon M340 Bmxp342000 Firmware · 25Modicon M340 Bmxp3420102 Firmware · 25Modicon Quantum Firmware · 25Easergy T300 Firmware · 24U.motion Builder · 24