CVE-2020-7478: Schneider Electric IGSS IGSSupdateservice Directory Traversal Information Disclosure Vulnerability
Published Mar 23, 2020
·Updated
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network when the IGSS Update Service is enabled.
Affected Software
1 affected component
Schneider-electric Interactive Graphical Scada System>=14.0<14.0.0.20009
Event History
Mar 23, 2020
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 29, 2026
Advisory Published
via ZDI·03:44 AM
Data Sourced
via ZDI·03:44 AM
DescriptionAffected Software