Vulnerability Description
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Att | Xmill | 0.7 |
| Schneider-Electric | Ecostruxure Control Expert | < 15.1 |
| Schneider-Electric | Ecostruxure Process Expert | < 2021 |
| Schneider-Electric | Remoteconnect | - |
| Schneider-Electric | Scadapack 470 | - |
| Schneider-Electric | Scadapack 474 | - |
| Schneider-Electric | Scadapack 570 | - |
| Schneider-Electric | Scadapack 574 | - |
| Schneider-Electric | Scadapack 575 | - |
Related Weaknesses (CWE)
References
- https://Claroty.comNot ApplicableThird Party Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-02MitigationRelease NotesThird Party Advisory
- https://Claroty.comNot ApplicableThird Party Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-02MitigationRelease NotesThird Party Advisory
FAQ
What is CVE-2022-26507?
CVE-2022-26507 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810,...
How severe is CVE-2022-26507?
CVE-2022-26507 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-26507?
Check the references section above for vendor advisories and patch information. Affected products include: Att Xmill, Schneider-Electric Ecostruxure Control Expert, Schneider-Electric Ecostruxure Process Expert, Schneider-Electric Remoteconnect, Schneider-Electric Scadapack 470.