schneider-electric interactive-graphical-scada-system CVE-2021-22760 is a vulnerability in Schneider Electric Interactive Graphical Scada System
Published on June 11, 2021

A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.

NVD

Weakness Type

Release of Invalid Pointer or Reference

The application attempts to return a memory resource to the system, but calls the wrong release function or calls the appropriate release function incorrectly.


Products Associated with CVE-2021-22760

Want to know whenever a new CVE is published for Schneider Electric Interactive Graphical Scada System? stack.watch will email you.

 

Exploit Probability

EPSS
0.43%
Percentile
62.47%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.