A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
** NO SOPORTADO CUANDO SE ASIGNÓ ** Se presenta un desbordamiento de búfer en la región heap de la memoria en XML Decompression DecodeTreeBlock en AT&T Labs Xmill versión 0.7. Un archivo de entrada diseñado puede conllevar a una ejecución de código remota. Esto no es lo mismo que cualquiera de: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, o CVE-2021-21830. NOTA: Esta vulnerabilidad sólo afecta a productos que ya no son soportados por el mantenedor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:P/I:P/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | PARTIAL |
| Integrity Impact | PARTIAL |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-787
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| att | xmill | 0.7 | <built-in method update of dict object at 0x7e60bbcf0600> | Application |
| schneider-electric | ecostruxure_control_expert | * | <built-in method update of dict object at 0x7e60a88a01c0> | Application |
| schneider-electric | ecostruxure_control_expert | 15.1 | <built-in method update of dict object at 0x7e60a88a0e40> | Application |
| schneider-electric | ecostruxure_process_expert | * | <built-in method update of dict object at 0x7e60a88a3c40> | Application |
| schneider-electric | remoteconnect | - | <built-in method update of dict object at 0x7e60bbcf0940> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:att:xmill:0.7:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.1:-:*:*:*:*:*:* |
| Yes | cpe:2.3:a:schneider-electric:ecostruxure_process_expert:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:remoteconnect:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:scadapack_470:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:scadapack_474:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:scadapack_570:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:scadapack_574:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:scadapack_575:-:*:*:*:*:*:*:* |