Vulnerabilities > Schneider Electric > Interactive Graphical Scada System > 14.0

DATE CVE VULNERABILITY TITLE RISK
2023-09-14 CVE-2023-4516 Missing Authentication for Critical Function vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
local
low complexity
schneider-electric CWE-306
7.8
2023-02-01 CVE-2022-24324 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-02-01 CVE-2022-2329 Integer Overflow or Wraparound vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages.
network
low complexity
schneider-electric CWE-190
critical
9.8
2023-01-30 CVE-2022-32522 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-01-30 CVE-2022-32523 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-01-30 CVE-2022-32524 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-01-30 CVE-2022-32525 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-01-30 CVE-2022-32526 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting value messages.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-01-30 CVE-2022-32527 Classic Buffer Overflow vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages.
network
low complexity
schneider-electric CWE-120
critical
9.8
2023-01-30 CVE-2022-32528 Missing Authentication for Critical Function vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGSS project report directory, potentially leading to a denial-of-service condition when an attacker sends specific messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
network
low complexity
schneider-electric CWE-306
critical
9.1