First published: Tue Mar 21 2023(Updated: )
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Custom Reports | <=16.0.0.23040 | |
Schneider-electric Igss Dashboard | <=16.0.0.23040 | |
Schneider-electric Igss Data Server | <=16.0.0.23040 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-27977.
The severity of CVE-2023-27977 is medium (5.3).
The affected software for this vulnerability includes Schneider-electric Custom Reports, Igss Dashboard, and Igss Data Server.
An attacker can exploit CVE-2023-27977 by sending specific crafted messages to the Data Server TCP port.
To fix CVE-2023-27977, it is recommended to apply the necessary security patch provided by Schneider Electric.