Impact
An out‑of‑bounds write (CWE‑787) exists in Schneider Electric’s IGSS Definition (Def.exe). Importing a malicious CGF file can cause memory corruption, leading to data loss or possibly arbitrary code execution. The flaw allows an attacker to affect the execution flow of the program and compromise confidentiality, integrity, or availability of the affected system.
Affected Systems
Schneider Electric IGSS Definition (Def.exe) is affected. No specific affected versions are listed, so all deployments of this product should be evaluated for the presence of the flaw.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score of <1 % suggests a low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Exploitation requires a malicious CGF file; depending on whether the file can be delivered locally or remotely, an attacker would need the ability to import such a file into IGSS Definition, a condition that is not detailed in the advisory but is inferred from the description.
OpenCVE Enrichment