Schneider Electric Igss Data Server vulnerabilities
18 known vulnerabilities affecting schneider_electric/igss_data_server.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH5MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-27978HIGHCVSS 7.8≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27978 [HIGH] CWE-502 CVE-2023-27978: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(Da
cvelistv5nvd
CVE-2023-27981HIGHCVSS 8.8≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27981 [HIGH] CWE-22 CVE-2023-27981: A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS
cvelistv5nvd
CVE-2023-27980HIGHCVSS 8.8≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27980 [HIGH] CWE-306 CVE-2023-27980: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.2
cvelistv5nvd
CVE-2023-27984HIGHCVSS 8.8≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27984 [HIGH] CWE-20 CVE-2023-27984: A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro
A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 an
cvelistv5nvd
CVE-2023-27982HIGHCVSS 8.8≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27982 [HIGH] CWE-345 CVE-2023-27982: A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server th
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim eventually opens a malicious dashbo
cvelistv5nvd
CVE-2023-27979MEDIUMCVSS 6.5≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27979 [MEDIUM] CWE-345 CVE-2023-27979: A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server th
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0
cvelistv5nvd
CVE-2023-27977MEDIUMCVSS 5.3≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27977 [MEDIUM] CWE-345 CVE-2023-27977: A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server th
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.2
cvelistv5nvd
CVE-2023-27983MEDIUMCVSS 5.3≥ V, ≤ 16.0.0.230402023-03-21
CVE-2023-27983 [MEDIUM] CWE-306 CVE-2023-27983: A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Da
cvelistv5nvd
CVE-2022-2329CRITICALCVSS 9.8≥ All, < V15.0.0.220732023-02-01
CVE-2022-2329 [CRITICAL] CWE-190 CVE-2022-2329: A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer ov
A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)
cvelistv5nvd
CVE-2022-24324CRITICALCVSS 9.8≥ All, < V15.0.0.220732023-02-01
CVE-2022-24324 [CRITICAL] CWE-120 CVE-2022-24324: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22073)
cvelistv5nvd
CVE-2022-32528CRITICALCVSS 9.1≥ All, < V15.0.0.221702023-01-30
CVE-2022-32528 [CRITICAL] CWE-306 CVE-2022-32528:
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could
cause acces
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could
cause access to manipulate and read specific files in the IGSS project report directory,
potentially leading to a denial-of-service condition when an attacker sends specific messages.
Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to
cvelistv5nvd
CVE-2022-32525CRITICALCVSS 9.8≥ All, < V15.0.0.221702023-01-30
CVE-2022-32525 [CRITICAL] CWE-120 CVE-2022-32525: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
cvelistv5nvd
CVE-2022-32526CRITICALCVSS 9.8≥ All, < V15.0.0.221702023-01-30
CVE-2022-32526 [CRITICAL] CWE-120 CVE-2022-32526: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting value messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
cvelistv5nvd
CVE-2022-32523CRITICALCVSS 9.8≥ All, < V15.0.0.221702023-01-30
CVE-2022-32523 [CRITICAL] CWE-120 CVE-2022-32523: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
cvelistv5nvd
CVE-2022-32529CRITICALCVSS 9.8≥ All, < V15.0.0.221702023-01-30
CVE-2022-32529 [CRITICAL] CWE-120 CVE-2022-32529: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
cvelistv5nvd
CVE-2022-32527CRITICALCVSS 9.8≥ All, < V15.0.0.221702023-01-30
CVE-2022-32527 [CRITICAL] CWE-120 CVE-2022-32527: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
cvelistv5nvd
CVE-2022-32522CRITICALCVSS 9.8≥ All, < V15.0.0.221702023-01-30
CVE-2022-32522 [CRITICAL] CWE-120 CVE-2022-32522: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
cvelistv5nvd
CVE-2022-32524CRITICALCVSS 9.8≥ All, < V15.0.0.221702023-01-30
CVE-2022-32524 [CRITICAL] CWE-120 CVE-2022-32524: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
cvelistv5nvd