9.8
CVE-2022-26507
- EPSS 6.7%
- Veröffentlicht 14.04.2022 13:15:11
- Zuletzt bearbeitet 21.11.2024 06:54:04
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Ecostruxure Control Expert Version < 15.1
Schneider-electric ≫ Ecostruxure Control Expert Version15.1 Update-
Schneider-electric ≫ Ecostruxure Process Expert Version < 2021
Schneider-electric ≫ Remoteconnect Version-
Schneider-electric ≫ Scadapack 470 Version-
Schneider-electric ≫ Scadapack 474 Version-
Schneider-electric ≫ Scadapack 570 Version-
Schneider-electric ≫ Scadapack 574 Version-
Schneider-electric ≫ Scadapack 575 Version-
Schneider-electric ≫ Scadapack 474 Version-
Schneider-electric ≫ Scadapack 570 Version-
Schneider-electric ≫ Scadapack 574 Version-
Schneider-electric ≫ Scadapack 575 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 6.7% | 0.909 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.