CVE-2023-27978
published 2023-03-21CVE-2023-27978: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data…
PriorityP346high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
6.48%
93.0th percentile
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | custom_reports | <= 16.0.0.23040 | — |
| schneider-electric | igss_dashboard | <= 16.0.0.23040 | — |
| schneider-electric | igss_data_server | <= 16.0.0.23040 | — |
| schneider_electric | custom_reports | V – 16.0.0.23040 | — |
| schneider_electric | igss_dashboard | V – 16.0.0.23040 | — |
| schneider_electric | igss_data_server | V – 16.0.0.23040 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric IGSS
cisa_ics·2023-03-23·CVSS 8.8
[HIGH] Schneider Electric IGSS
ICS Advisory
##
Schneider Electric IGSS
Release DateMarch 23, 2023
Alert CodeICSA-23-082-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: IGSS (Interactive Graphical SCADA System)
- Vulnerabilities: Missing Authentication for Critical Function, Insufficient Verification of Data Authenticity, Deserialization of Untrusted Data, Improper Limitation of a Pathname to a Restricted Directory, and Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a denial-of-service condition, as well as the loss, addition, or modification of dashboards or report files in the IGSS Report folder. Successful exploitation of these vul
GHSA
GHSA-j943-j589-56x5: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data
ghsa_unreviewed·2023-03-21
CVE-2023-27978 [HIGH] CWE-502 GHSA-j943-j589-56x5: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-21
Published