CVE-2023-27983: Medium severity schneider-electric custom reports vulnerability
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-27983?
CVE-2023-27983 is a vulnerability that allows deletion of reports from the IGSS project report directory, leading to data loss.
What is the severity level of CVE-2023-27983?
CVE-2023-27983 has a severity level of medium (5.3).
Which products are affected by CVE-2023-27983?
The affected products include Schneider-electric Custom Reports, Schneider-electric Igss Dashboard, and Schneider-electric Igss Data Server.
How can an attacker abuse the vulnerability in CVE-2023-27983?
An attacker can abuse CVE-2023-27983 by deleting reports from the IGSS project report directory, leading to data loss.
Is there a reference link for more information about CVE-2023-27983?
Yes, you can find more information about CVE-2023-27983 at the following link: [reference link](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-04.pdf).