Rewterz Threat Alert – Microsoft Exchange Servers Hit With DEARCRY Ransomware
March 12, 2021Rewterz Threat Advisory – ICS: Siemens SIMATIC S7-PLCSIM Denial of Service Vulnerability
March 12, 2021Rewterz Threat Alert – Microsoft Exchange Servers Hit With DEARCRY Ransomware
March 12, 2021Rewterz Threat Advisory – ICS: Siemens SIMATIC S7-PLCSIM Denial of Service Vulnerability
March 12, 2021Severity
High
Analysis Summary
CVE-2021-22709
This vulnerability could result in loss of data or remote code execution when a malicious CGF (configuration group file) file is imported into an IGSS Definition.
CVE-2021-22710
This vulnerability could result in loss of data or remote code execution when a malicious CGF file is imported into an IGSS Definition.
CVE-2021-22711
This vulnerability could result in arbitrary read or write conditions due to missing validation of input data when a malicious CGF file is imported into an IGSS Definition.
CVE-2021-22712
This vulnerability could result in arbitrary read or write conditions due to an unchecked pointer address when a malicious CGF file is imported into an IGSS Definition.
Impact
Remote code execution
Affected Vendors
Schneider Electric
Affected Products
IGSS Definition (Def.exe) Version 15.0.0.21041 and prior
Remediation
Refer to ICS advisory for the complete list of affected products and their respective patches.