Insufficient Data Authenticity Verification in IGSS Data Server Products
CVE-2023-27982
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 21 March 2023
What is CVE-2023-27982?
A vulnerability in Schneider Electric's IGSS Data Server products allows attackers to exploit insufficient verification of data authenticity. This issue can be triggered by sending specially crafted messages to the Data Server's TCP port. If a victim opens a manipulated dashboard file, it could lead to remote code execution. This vulnerability affects multiple versions of the IGSS Data Server, IGSS Dashboard, and Custom Reports.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Custom Reports (RMS16.dll) V <= 16.0.0.23040
IGSS Dashboard (DashBoard.exe) V <= 16.0.0.23040
IGSS Data Server(IGSSdataServer.exe) V <= 16.0.0.23040
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved