Deserialization Vulnerability in IGSS Dashboard and Data Server by Schneider Electric
CVE-2023-27978
7.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 21 March 2023
Summary
A vulnerability exists in Schneider Electric's IGSS products, specifically within the Dashboard module, which allows for deserialization of untrusted data. This flaw can be exploited when users open a specially crafted file, potentially enabling remote code execution by an attacker. The affected software versions include IGSS Data Server, IGSS Dashboard, and Custom Reports, all vulnerable up to version 16.0.0.23040. Organizations using these products should prioritize mitigation strategies to safeguard their systems against possible exploitation.
Affected Version(s)
Custom Reports (RMS16.dll) V <= 16.0.0.23040
IGSS Dashboard (DashBoard.exe) V <= 16.0.0.23040
IGSS Data Server(IGSSdataServer.exe) V <= 16.0.0.23040
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved