First published: Mon Jan 30 2023(Updated: )
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGSS project report directory, potentially leading to a denial-of-service condition when an attacker sends specific messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Interactive Graphical Scada System | <=15.0.0.22170 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32528 is a vulnerability that exists in the Schneider-electric Interactive Graphical Scada System (IGSS) software, allowing unauthorized access and potential denial-of-service attacks.
CVE-2022-32528 affects IGSS versions up to and including 15.0.0.22170, allowing attackers to manipulate and read specific files in the IGSS project report directory, leading to potential denial-of-service.
The severity of CVE-2022-32528 is rated as critical with a CVSS score of 9.1.
To fix the CVE-2022-32528 vulnerability, it is recommended to update IGSS software to a version that includes the necessary patches or fixes provided by Schneider-electric.
You can find more information about CVE-2022-32528, including the mitigation steps, in the security notice document provided by Schneider-electric. The document can be accessed at the following link: [link]