Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown

CVE-2020-7551

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
Attacker Value
Unknown

CVE-2020-7479

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS Update Service.
Attacker Value
Unknown

CVE-2020-7478

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network when the IGSS Update Service is enabled.
Attacker Value
Unknown

CVE-2019-6827

Disclosure Date: July 15, 2019 (last updated November 27, 2024)
A CWE-787: Out-of-bounds Write vulnerability exists in Interactive Graphical SCADA System (IGSS), Version 14 and prior, which could cause a software crash when data in the mdb database is manipulated.
Attacker Value
Unknown

CVE-2017-9967

Disclosure Date: February 12, 2018 (last updated November 26, 2024)
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
0
Attacker Value
Unknown

CVE-2017-6033

Disclosure Date: April 07, 2017 (last updated November 26, 2024)
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.
0
Attacker Value
Unknown

CVE-2013-0657

Disclosure Date: January 21, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.
0