CWE-119 Improper Restriction of Operations Within a Memory Buffer
A critical integer overflow vulnerability that could enable an attacker to send a specially crafted TCP packet to the device to either cause it to reboot the meter or remotely run code of their choice, depending on the architecture of the targeted device.

Read more: Claroty Uncovers Vulnerabilities in Schneider Electric Smart Meters

Risk Information

  • CVE ID
  • CVE-2021-22714
  • Vendor
  • Schneider Electric
  • Product
  • PowerLogic ION
  • CVSS v3
  • 9.8