CVE-2023-27980
published 2023-03-21CVE-2023-27980: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.88%
54.9th percentile
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior)
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | custom_reports | <= 16.0.0.23040 | — |
| schneider-electric | igss_dashboard | <= 16.0.0.23040 | — |
| schneider-electric | igss_data_server | <= 16.0.0.23040 | — |
| schneider_electric | custom_reports | V – 16.0.0.23040 | — |
| schneider_electric | igss_dashboard | V – 16.0.0.23040 | — |
| schneider_electric | igss_data_server | V – 16.0.0.23040 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric IGSS
cisa_ics·2023-03-23·CVSS 8.8
[HIGH] Schneider Electric IGSS
ICS Advisory
##
Schneider Electric IGSS
Release DateMarch 23, 2023
Alert CodeICSA-23-082-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: IGSS (Interactive Graphical SCADA System)
- Vulnerabilities: Missing Authentication for Critical Function, Insufficient Verification of Data Authenticity, Deserialization of Untrusted Data, Improper Limitation of a Pathname to a Restricted Directory, and Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a denial-of-service condition, as well as the loss, addition, or modification of dashboards or report files in the IGSS Report folder. Successful exploitation of these vul
GHSA
GHSA-7x8q-p6x2-5gq2: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malic
ghsa_unreviewed·2023-03-21
CVE-2023-27980 [HIGH] CWE-306 GHSA-7x8q-p6x2-5gq2: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malic
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-21
Published