<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:23:46 +0000</lastBuildDate>
    <item>
      <title>certfr-2021-avi-443 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-443</link>
      <description>certfr-2021-avi-443</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-443</guid>
    </item>
    <item>
      <title>cnvd-2021-42149</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-42149</link>
      <description>cnvd-2021-42149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-42149</guid>
    </item>
    <item>
      <title>EUVD-2026-23085</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-23085</link>
      <description>EUVD-2026-23085</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-23085</guid>
    </item>
    <item>
      <title>fkie_cve-2021-22760</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-22760</link>
      <description>&lt;p&gt;A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-22760</guid>
    </item>
    <item>
      <title>GHSA-486p-jw3h-72gh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-486p-jw3h-72gh</link>
      <description>&lt;p&gt;A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-486p-jw3h-72gh</guid>
    </item>
    <item>
      <title>gsd-2021-22760</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-22760</link>
      <description>gsd-2021-22760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-22760</guid>
    </item>
    <item>
      <title>ICSA-21-159-04 — Schneider Electric IGSS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-159-04</link>
      <description>&lt;p&gt;Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious CGF file is imported to IGSS Definition.CVE-2021-22750 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in disclosure of information or execution of arbitrary code due to lack of input validation when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2021-22751 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in loss of data or remote code execution due to missing size checks when a malicious WSP (Workspace) file is being parsed by IGSS Definition.CVE-2021-22752 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious WSP file is being parsed by IGSS Definition.CVE-2021-22753 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in loss of data or…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious CGF file is imported to IGSS Definition.CVE-2021-22750 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in disclosure of information or execution of arbitrary code due to lack of input validation when a malicious CGF (Configuration Group File) is imported to IGSS Definition.CVE-2021-22751 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in loss of data or remote code execution due to missing size checks when a malicious WSP (Workspace) file is being parsed by IGSS Definition.CVE-2021-22752 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in loss of data or remote code execution due to missing length checks when a malicious WSP file is being parsed by IGSS Definition.CVE-2021-22753 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Exploitation of this vulnerability could result in loss of data or…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-159-04</guid>
    </item>
    <item>
      <title>SEVD-2021-159-01 — IGSS (Interactive Graphical SCADA System)</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2021-159-01</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the Interactive Graphical SCADA &#13;
System (IGSS) product. &#13;
The IGSS product is a state-of-the art SCADA system used for monitoring and controlling &#13;
industrial processes. IGSS communicates with all major industry standard PLC drivers. &#13;
Failure to apply the remediations provided below may risk remote code execution, which could &#13;
result in an attacker gaining access to the Windows Operating System on the machine used to &#13;
import CGF and WSP files, typically a step performed during system design time.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in the Interactive Graphical SCADA &#13;
System (IGSS) product. &#13;
The IGSS product is a state-of-the art SCADA system used for monitoring and controlling &#13;
industrial processes. IGSS communicates with all major industry standard PLC drivers. &#13;
Failure to apply the remediations provided below may risk remote code execution, which could &#13;
result in an attacker gaining access to the Windows Operating System on the machine used to &#13;
import CGF and WSP files, typically a step performed during system design time.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2021-159-01</guid>
    </item>
  </channel>
</rss>
