CVE-2022-26507
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
14/04/2022
Last modified:
03/08/2024
Description
A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:att:xmill:0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:* | 15.1 (excluding) | |
| cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:ecostruxure_process_expert:*:*:*:*:*:*:*:* | 2021 (excluding) | |
| cpe:2.3:h:schneider-electric:scadapack_470:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:scadapack_474:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:scadapack_570:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:scadapack_574:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:scadapack_575:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schneider-electric:remoteconnect:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



