CVE-2023-27979
published 2023-03-21CVE-2023-27979: A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
0.24%
15.4th percentile
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | custom_reports | <= 16.0.0.23040 | — |
| schneider-electric | igss_dashboard | <= 16.0.0.23040 | — |
| schneider-electric | igss_data_server | <= 16.0.0.23040 | — |
| schneider_electric | custom_reports | V – 16.0.0.23040 | — |
| schneider_electric | igss_dashboard | V – 16.0.0.23040 | — |
| schneider_electric | igss_data_server | V – 16.0.0.23040 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric IGSS
cisa_ics·2023-03-23·CVSS 8.8
[HIGH] Schneider Electric IGSS
ICS Advisory
##
Schneider Electric IGSS
Release DateMarch 23, 2023
Alert CodeICSA-23-082-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: IGSS (Interactive Graphical SCADA System)
- Vulnerabilities: Missing Authentication for Critical Function, Insufficient Verification of Data Authenticity, Deserialization of Untrusted Data, Improper Limitation of a Pathname to a Restricted Directory, and Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a denial-of-service condition, as well as the loss, addition, or modification of dashboards or report files in the IGSS Report folder. Successful exploitation of these vul
GHSA
GHSA-pfhh-873g-hhx7: A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS p
ghsa_unreviewed·2023-03-21
CVE-2023-27979 [HIGH] CWE-345 GHSA-pfhh-873g-hhx7: A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS p
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-21
Published