Insufficient Data Authenticity Verification in IGSS Data Server Products
CVE-2023-27982
8.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 21 March 2023
Summary
A vulnerability in Schneider Electric's IGSS Data Server products allows attackers to exploit insufficient verification of data authenticity. This issue can be triggered by sending specially crafted messages to the Data Server's TCP port. If a victim opens a manipulated dashboard file, it could lead to remote code execution. This vulnerability affects multiple versions of the IGSS Data Server, IGSS Dashboard, and Custom Reports.
Affected Version(s)
Custom Reports (RMS16.dll) V <= 16.0.0.23040
IGSS Dashboard (DashBoard.exe) V <= 16.0.0.23040
IGSS Data Server(IGSSdataServer.exe) V <= 16.0.0.23040
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved