peter bassill · operator
$ cve CVE-2021-22823 JSON

CVE-2021-22823

9.1
CRITICAL · CVSS 3.1 · EPSS 21.4% (pctl 98)

Patch early

EPSS 21.4% — above the 10% action threshold.

Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS21.39% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2022-02-11
Last modified2026-06-17

Affected (1)

VendorProduct
schneider-electricinteractive graphical scada system data collector

References

→ the Explorer  ·  watch your stack  ·  NVD