The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric IGSS Definition (Def.exe) version 15.0.0.21041 and prior
- Summary
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could result in loss of data or remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
- Remediation
- Version 15.0.0.21042 of the IGSS Definition module: Def.exe includes a fix for each of these vulnerabilities and is available for download through IGSS Master > Update IGSS Software or here: Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric's Customer Care Center if you need assistance removing a patch.
