Interactive Graphical Scada System

Vendor:

First CVE: Jan 21, 2013 · Active for 13 years

43
Total CVEs
More Total CVEs than 98% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Interactive Graphical Scada System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2013
13 years ago
Most Recent CVE
Sep 14, 2023
1,047 days ago

CVE Severity & Scoring

Interactive Graphical Scada System43 CVEs
All CVEs352,785 CVEs
HighCritical
Attack Vector
Local31 (72.1%)
Network11 (25.6%)
Unknown1 (2.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (97.7%)
High0 (0.0%)
Unknown1 (2.3%)
User Interaction
None14 (32.6%)
Unknown1 (2.3%)
Required28 (65.1%)
Privileges Required
Low3 (7.0%)
High0 (0.0%)
None39 (90.7%)
Unknown1 (2.3%)

Top CVEs

Signals from CVEs in this product scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-123
Jan 21, 201310.053NOYES
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when
Feb 1, 20239.832NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attac
Feb 1, 20239.831NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an atta
Jan 30, 20239.831NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an atta
Jan 30, 20239.830NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an atta
Jan 30, 20239.830NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an atta
Jan 30, 20239.830NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an atta
Jan 30, 20239.830NONO
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an atta
Jan 30, 20239.830NONO
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGSS project report directory, po
Jan 30, 20239.128NONO

Exploit Exposure

Signals from CVEs in this product scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.3% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (43 CVEs).

Media Mentions

Signals from CVEs in this product scope (43 CVEs).

Top CNAs Publishing CVEs For Interactive Graphical Scada System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0110.021.3%01