← Back to browse · API

CVE-2022-2329

Severity
CRITICAL
CVSS
9.8
EPSS
0.02141
Risk score
39.95
CISA KEV
No
PoC
No
Published
2023-02-01
Modified
2025-02-05
First seen
2026-08-07
Aliases
EUVD-2022-34598, GHSA-2384-WFR6-9J3J
Products
Schneider Electric:IGSS Data Server (IGSSdataServer.exe) All <V15.0.0.22073
Sources
euvd EUVD-2022-34598

Description

A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)

References