← Vulnerability feed

Vulnerability record · CVE-2022-32523 · published 30 January 2023

CVE-2022-32523: Schneider-electric interactive graphical scada system classic buffer overflow vulnerability

Schneider Electric · Interactive Graphical Scada System

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)

9.8 CVSS 3.1 Critical EPSS 1.3% · top 31.4% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-32523 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-0657Schneider-electric interactive graphical scada system memory buffer overflow vulnerabilityStack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitra…EPSS 21%9.8CVE-2022-2329Schneider-electric interactive graphical scada system integer overflow vulnerabilityA CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentia…EPSS 2.1%9.8CVE-2022-24324Schneider-electric interactive graphical scada system classic buffer overflow vulnerabilityA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remo…EPSS 1.2%9.8CVE-2022-32529Schneider-electric interactive graphical scada system classic buffer overflow vulnerabilityA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…EPSS 1.3%9.8CVE-2022-32522Schneider-electric interactive graphical scada system classic buffer overflow vulnerabilityA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…EPSS 1.1%9.8CVE-2022-32524Schneider-electric interactive graphical scada system classic buffer overflow vulnerabilityA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…EPSS 1.3%9.8CVE-2022-32525Schneider-electric interactive graphical scada system classic buffer overflow vulnerabilityA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…EPSS 1.3%9.8CVE-2022-32526Schneider-electric interactive graphical scada system classic buffer overflow vulnerabilityA CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to rem…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2022-32523), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.