Missing Authentication in IGSS Data Server by Schneider Electric
CVE-2022-32528

8.6HIGH

Key Information:

Vendor
CVE Published:
30 January 2023

Summary

A vulnerability exists in the IGSS Data Server due to missing authentication mechanisms that could allow an unauthorized user to access and manipulate sensitive files within the project report directory. This lack of authentication poses a risk of potential denial-of-service conditions when specific messages are transmitted by an attacker. Products affected include all versions prior to V15.0.0.22170.

Affected Version(s)

IGSS Data Server (IGSSdataServer.exe) All

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.