Missing Authentication in IGSS Data Server and Dashboard by Schneider Electric
CVE-2023-27983

6.5MEDIUM

Summary

A vulnerability exists in the Data Server TCP interface that allows unauthorized users to delete reports from the IGSS project report directory. This exploitation can lead to significant data loss as attackers can misuse this functionality to manipulate or erase critical project reports. The affected components include the IGSS Data Server, IGSS Dashboard, and Custom Reports, all having versions V16.0.0.23040 and prior. Organizations using these products should apply security measures to prevent unauthorized access.

Affected Version(s)

Custom Reports (RMS16.dll) V <= 16.0.0.23040

IGSS Dashboard (DashBoard.exe) V <= 16.0.0.23040

IGSS Data Server(IGSSdataServer.exe) V <= 16.0.0.23040

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.