CVE-2021-22805

CRITICAL

IGSS dc.exe <15.0.0.21243 - Missing Authentication

Title source: llm
STIX 2.1

Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0023
EPSS Percentile 46.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
schneider-electric/interactive_graphical_scada_system_data_collector < 15.0.0.21243
Published Feb 11, 2022
Tracked Since Feb 18, 2026