CVE Published: 09/02/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: schneider |
Vendor: n/a |
Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) Status : PUBLISHED
CVE-2022-24312 Description
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)