The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric IGSS Data Server (IGSSdataServer.exe) version 15.0.0.22073 and prior
- Summary
- A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages.
- Remediation
- Version 15.0.0.22074 of IGSS Data Server includes a correction for this vulnerability and is available for download through IGSS Master > Update IGSS Software or here: https://igss.schneider-electric.com/igss/igssupdates/v150/IGSSUPDATE.ZIP
