
CVE-2022-32525
https://notcve.org/view.php?id=CVE-2022-32525
30 Jan 2023 — A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170) Existe una vulnerabilidad CWE-120: copia del búfer sin comprobar el tamaño de la entrada que podría provocar un desbordamiento de búfer en la región stack de la memoria, lo que podría provoca... • https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification_V2.pdf • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2021-22758
https://notcve.org/view.php?id=CVE-2021-22758
11 Jun 2021 — A CWE-824: Access of uninitialized pointer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack validation of user-supplied input data, when a malicious CGF file is imported to IGSS Definition. Un CWE-824: Se presenta una vulnerabilidad de acceso a punteros no inicializados en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores, que podría resultar en la pérdida de datos o una ejecución de código remota deb... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-824: Access of Uninitialized Pointer •

CVE-2021-22756
https://notcve.org/view.php?id=CVE-2021-22756
11 Jun 2021 — A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of user-supplied data validation, when a malicious CGF file is imported to IGSS Definition. Un CWE-125: Se presenta una vulnerabilidad de lectura fuera de límites en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores, que podría resultar en una divulgación de información o en una ejecución de código remota debid... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-125: Out-of-bounds Read •

CVE-2021-22757
https://notcve.org/view.php?id=CVE-2021-22757
11 Jun 2021 — A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied input data, when a malicious CGF file is imported to IGSS Definition. Un CWE-125: Se presenta una vulnerabilidad de lectura fuera de límites en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores, que podría resultar en una divulgación de información o en una ejecución de código ... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-125: Out-of-bounds Read •

CVE-2021-22760
https://notcve.org/view.php?id=CVE-2021-22760
11 Jun 2021 — A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition. Un CWE-763: Se presenta una vulnerabilidad de puntero o referencia no válida en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores que podría resultar en una pérdida de información o una ejecución de código r... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-763: Release of Invalid Pointer or Reference •

CVE-2021-22755
https://notcve.org/view.php?id=CVE-2021-22755
11 Jun 2021 — A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data, when a malicious CGF file is imported to IGSS Definition. Un CWE-787: Se presenta una vulnerabilidad de escritura fuera de límites en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores, que podría resultar en una divulgación de información o en una ejecución de código rem... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-787: Out-of-bounds Write •

CVE-2021-22759
https://notcve.org/view.php?id=CVE-2021-22759
11 Jun 2021 — A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to use of unchecked input data, when a malicious CGF file is imported to IGSS Definition. Un CWE-416: Se presenta una vulnerabilidad de uso de memoria previamente liberada en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores, que podría resultar en la pérdida de datos o una ejecución de código remota debido al uso de datos de entrada n... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-416: Use After Free •

CVE-2021-22754
https://notcve.org/view.php?id=CVE-2021-22754
11 Jun 2021 — A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition. Un CWE-787: Se presenta una vulnerabilidad de escritura fuera de límites en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores, que podría resultar en la pérdida de datos o una ejecución de código remota debido a una falta ... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-787: Out-of-bounds Write •

CVE-2021-22751
https://notcve.org/view.php?id=CVE-2021-22751
11 Jun 2021 — A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition. Un CWE-787: Se presenta una vulnerabilidad de escritura fuera de límites en IGSS Definition (Def.exe) versiones V15.0.0.21140 y anteriores, que podría resultar en una divulgación de información o en una ejecución... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-787: Out-of-bounds Write •

CVE-2021-22750 – Schneider Electric IGSS CGF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-22750
10 Jun 2021 — A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition. Un CWE-787: Se presenta una vulnerabilidad de escritura fuera de límites en IGSS Definition (Def.exe) versiones V15.0.0.21041 y anteriores que podría resultar en la pérdida de datos o una ejecución de código remota debido a una falta de comprobaciones de longit... • http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 • CWE-787: Out-of-bounds Write •