Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27cr-vrc4-8c94

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to missing validation of input data.

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to missing validation of input data.

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 7.8
nvd
почти 5 лет назад

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to IGSS Definition due to missing validation of input data.

CVSS3: 8.8
fstec
почти 5 лет назад

Уязвимость интерактивной графической SCADA системы Interactive Graphical SCADA System (IGSS), вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить чтение или запись произвольных файлов

EPSS

Процентиль: 32%
0.00127
Низкий

Дефекты

CWE-119