CVE-2023-27983
published 2023-03-21CVE-2023-27983: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.44%
35.4th percentile
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | custom_reports | <= 16.0.0.23040 | — |
| schneider-electric | igss_dashboard | <= 16.0.0.23040 | — |
| schneider-electric | igss_data_server | <= 16.0.0.23040 | — |
| schneider_electric | custom_reports | V – 16.0.0.23040 | — |
| schneider_electric | igss_dashboard | V – 16.0.0.23040 | — |
| schneider_electric | igss_data_server | V – 16.0.0.23040 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric IGSS
cisa_ics·2023-03-23·CVSS 8.8
[HIGH] Schneider Electric IGSS
ICS Advisory
##
Schneider Electric IGSS
Release DateMarch 23, 2023
Alert CodeICSA-23-082-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: IGSS (Interactive Graphical SCADA System)
- Vulnerabilities: Missing Authentication for Critical Function, Insufficient Verification of Data Authenticity, Deserialization of Untrusted Data, Improper Limitation of a Pathname to a Restricted Directory, and Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a denial-of-service condition, as well as the loss, addition, or modification of dashboards or report files in the IGSS Report folder. Successful exploitation of these vul
GHSA
GHSA-m2r7-25m3-rr8g: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports fro
ghsa_unreviewed·2023-03-21
CVE-2023-27983 [MEDIUM] CWE-306 GHSA-m2r7-25m3-rr8g: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports fro
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-21
Published