CVE-2023-4516
published 2023-09-14CVE-2023-4516: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.9th percentile
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change update source, potentially leading to remote
code execution when the attacker force an update containing malicious content.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | interactive_graphical_scada_system | <= 16.0.0.23211 | — |
| schneider_electric | igss_update_service | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4c87-xqpv-r7h5: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change up
ghsa_unreviewed·2023-09-14
CVE-2023-4516 [HIGH] CWE-306 GHSA-4c87-xqpv-r7h5: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change up
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change update source, potentially leading to remote
code execution when the attacker force an update containing malicious content.
CISA ICS
Schneider Electric IGSS
cisa_ics·2023-10-12·CVSS 7.8
[HIGH] Schneider Electric IGSS
ICS Advisory
##
Schneider Electric IGSS
Release DateOctober 12, 2023
Alert CodeICSA-23-285-16
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: low attack complexity
- Vendor: Schneider Electric
- Equipment: IGSS (Interactive Graphical SCADA System)
- Vulnerability: Missing Authentication for Critical Function
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow arbitrary code execution or loss of control of the SCADA system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneider Electric reports these vulnerabilities affect the following IGSS (Interactive Graphical SCADA System) products:
- IGSS Update Service (IGSSupdateservice.exe): v16.0.0.23211 and prior.
## 3.2 Vulnerability Overview
3.2.1 Missing Au
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-14
Published