Description
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.
Published: 2026-07-29
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write (CWE‑787) exists in Schneider Electric’s IGSS Definition (Def.exe). Importing a malicious CGF file can cause memory corruption, leading to data loss or possibly arbitrary code execution. The flaw allows an attacker to affect the execution flow of the program and compromise confidentiality, integrity, or availability of the affected system.

Affected Systems

Schneider Electric IGSS Definition (Def.exe) is affected. No specific affected versions are listed, so all deployments of this product should be evaluated for the presence of the flaw.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, while the EPSS score of <1 % suggests a low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Exploitation requires a malicious CGF file; depending on whether the file can be delivered locally or remotely, an attacker would need the ability to import such a file into IGSS Definition, a condition that is not detailed in the advisory but is inferred from the description.

Generated by OpenCVE AI on August 3, 2026 at 13:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor’s latest security update that resolves the out‑of‑bounds write in IGSS Definition.
  • Restrict or deny the import of CGF files from untrusted or unknown sources, or from network locations where attackers may place malicious files.
  • Implement network segmentation and strict access controls to limit exposure of IGSS Definition instances to potential attackers.

Generated by OpenCVE AI on August 3, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in IGSS Definition Leading to Possible Arbitrary Code Execution

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Schneider Electric
Schneider Electric igss Definition (def.exe)
Vendors & Products Schneider Electric
Schneider Electric igss Definition (def.exe)
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Schneider Electric Igss Definition (def.exe)
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2026-07-29T14:19:12.306Z

Reserved: 2026-06-22T17:23:06.940Z

Link: CVE-2026-12927

cve-icon Vulnrichment

Updated: 2026-07-29T14:19:06.467Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T13:17:36.300

Modified: 2026-07-30T16:43:03.817

Link: CVE-2026-12927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:30:04Z

Weaknesses