Threat Encyclopedia

SE.IGSS.IGSSdataServer.exe.Opcode.6.Out.Of.Bounds.Write

description-logoDescription

This indicates an attack attempt to exploit an Out of Bound Write Vulnerability in Schneider Electric IGSS.
This vulnerability is due to an out-of-bounds write when processing Opcode 5 (ONL) messages sent to the IGSSDataServer.exe process. A remote, unauthenticated attacker could exploit this vulnerability by sending a maliciously crafted packet to the target service. Successful exploitation could allow the attacker to potentially execute arbitrary code on the target system in the context of the IGSSDataServer process.

affected-products-logoAffected Products

Schneider Electric IGSS prior to 15.0.0.22170

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

CVE References

CVE-2022-32525

Telemetry logoTelemetry