CVE-2022-32523

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:06

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad CWE-120: copia del búfer sin comprobar el tamaño de la entrada que podría provocar un desbordamiento de búfer en la región stack de la memoria, lo que podría provocar la ejecución remota de código cuando un atacante envía mensajes de solicitud de datos en línea especialmente manipulados. Productos afectados: IGSS Data Server - IGSSdataServer.exe (Versiones anteriores a V15.0.0.22170)
References () https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification_V2.pdf - Patch, Vendor Advisory () https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification_V2.pdf - Patch, Vendor Advisory

Information

Published : 2023-01-30 23:15

Updated : 2024-11-21 07:06


NVD link : CVE-2022-32523

Mitre link : CVE-2022-32523

CVE.ORG link : CVE-2022-32523


JSON object : View

Products Affected

schneider-electric

  • interactive_graphical_scada_system
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')