Insufficient Data Verification in Schneider Electric IGSS Data Server
CVE-2023-27977
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 21 March 2023
Summary
The vulnerability identified in Schneider Electric's IGSS Data Server originates from inadequate verification of data authenticity. This flaw can be exploited by attackers to send carefully crafted messages to the Data Server's TCP port, allowing unauthorized access to delete critical files within the IGSS project report directory. Such actions can result in significant data loss and compromise the integrity of user operations. Affected products include the IGSS Data Server, IGSS Dashboard, and Custom Reports, all of which are vulnerable up to version 16.0.0.23040.
Affected Version(s)
Custom Reports (RMS16.dll) V <= 16.0.0.23040
IGSS Dashboard (DashBoard.exe) V <= 16.0.0.23040
IGSS Data Server(IGSSdataServer.exe) V <= 16.0.0.23040
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved