CVE-2022-2329 is a critical integer overflow vulnerability (CWE-190) affecting the IGSS Data Server (IGSSdataServer.exe) in versions prior to V15.0.0.22073. An unauthenticated attacker can exploit this by sending specially crafted messages, leading to a heap-based buffer overflow. This vulnerability carries a CVSS v3.1 score of 9.8 (CRITICAL), indicating a high risk of denial of service and potential remote code execution due to its network-based attack vector and low complexity. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.0.22074CPE matchmatch criteria | cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Schneider Electric IGSS Data Server v15.0.0.22073 Integer Overflow
Apr 19, 2022Schneider Electric IGSS Data Server v15.0.0.22073 Integer Overflow
Apr 19, 2022Schneider Electric IGSS Data Server v15.0.0.22073 Integer Overflow
Apr 19, 2022