CVE-2022-32529

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:06

Type Values Removed Values Added
References () https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification_V2.pdf - Patch, Vendor Advisory () https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification_V2.pdf - Patch, Vendor Advisory
Summary
  • (es) Existe una vulnerabilidad CWE-120: copia del búfer sin comprobar el tamaño de la entrada que podría provocar un desbordamiento de búfer en la región stack de la memoria, lo que podría provocar la ejecución remota de código cuando un atacante envía mensajes de solicitud de datos de registro especialmente manipulados. Productos afectados: IGSS Data Server - IGSSdataServer.exe (Versiones anteriores a V15.0.0.22170)

Information

Published : 2023-01-30 23:15

Updated : 2024-11-21 07:06


NVD link : CVE-2022-32529

Mitre link : CVE-2022-32529

CVE.ORG link : CVE-2022-32529


JSON object : View

Products Affected

schneider-electric

  • interactive_graphical_scada_system
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')