First published: Tue Mar 21 2023(Updated: )
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Custom Reports | <=16.0.0.23040 | |
Schneider-electric Igss Dashboard | <=16.0.0.23040 | |
Schneider-electric Igss Data Server | <=16.0.0.23040 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-27978 is high, with a severity value of 7.8.
CVE-2023-27978 is a CWE-502: Deserialization of Untrusted Data vulnerability in the Dashboard module that could lead to remote code execution if a user opens a malicious file.
The affected products by CVE-2023-27978 are Schneider-electric Custom Reports, Schneider-electric Igss Dashboard, and Schneider-electric Igss Data Server, all with version up to and including 16.0.0.23040.
The CVE-2023-27978 vulnerability can be exploited by an attacker who convinces the user to open a malicious file, leading to the execution of remote code.
Yes, you can find the security notice and detailed information about CVE-2023-27978 at the following reference: [here](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-04.pdf).