Insufficient Data Verification in Schneider Electric IGSS Data Server
CVE-2023-27977

6.5MEDIUM

Summary

The vulnerability identified in Schneider Electric's IGSS Data Server originates from inadequate verification of data authenticity. This flaw can be exploited by attackers to send carefully crafted messages to the Data Server's TCP port, allowing unauthorized access to delete critical files within the IGSS project report directory. Such actions can result in significant data loss and compromise the integrity of user operations. Affected products include the IGSS Data Server, IGSS Dashboard, and Custom Reports, all of which are vulnerable up to version 16.0.0.23040.

Affected Version(s)

Custom Reports (RMS16.dll) V <= 16.0.0.23040

IGSS Dashboard (DashBoard.exe) V <= 16.0.0.23040

IGSS Data Server(IGSSdataServer.exe) V <= 16.0.0.23040

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.