Missing Authentication in IGSS Data Server and Dashboard by Schneider Electric
CVE-2023-27983
6.5MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 21 March 2023
What is CVE-2023-27983?
A vulnerability exists in the Data Server TCP interface that allows unauthorized users to delete reports from the IGSS project report directory. This exploitation can lead to significant data loss as attackers can misuse this functionality to manipulate or erase critical project reports. The affected components include the IGSS Data Server, IGSS Dashboard, and Custom Reports, all having versions V16.0.0.23040 and prior. Organizations using these products should apply security measures to prevent unauthorized access.
Affected Version(s)
Custom Reports (RMS16.dll) V <= 16.0.0.23040
IGSS Dashboard (DashBoard.exe) V <= 16.0.0.23040
IGSS Data Server(IGSSdataServer.exe) V <= 16.0.0.23040