Rewterz
Rewterz Threat Alert – Microsoft Exchange Servers Hit With DEARCRY Ransomware
March 12, 2021
Rewterz
Rewterz Threat Advisory – ICS: Siemens SIMATIC S7-PLCSIM Denial of Service Vulnerability
March 12, 2021

Rewterz Threat Advisory – ICS: Schneider Electric IGSS SCADA Software

Severity

High

Analysis Summary

CVE-2021-22709 

This vulnerability could result in loss of data or remote code execution when a malicious CGF (configuration group file) file is imported into an IGSS Definition.

CVE-2021-22710 

This vulnerability could result in loss of data or remote code execution when a malicious CGF file is imported into an IGSS Definition.

CVE-2021-22711 

This vulnerability could result in arbitrary read or write conditions due to missing validation of input data when a malicious CGF file is imported into an IGSS Definition.

CVE-2021-22712

This vulnerability could result in arbitrary read or write conditions due to an unchecked pointer address when a malicious CGF file is imported into an IGSS Definition.

Impact

Remote code execution

Affected Vendors

Schneider Electric

Affected Products

IGSS Definition (Def.exe) Version 15.0.0.21041 and prior

Remediation

Refer to ICS advisory for the complete list of affected products and their respective patches.

https://us-cert.cisa.gov/ics/advisories/icsa-21-070-01