First published: Tue Mar 21 2023(Updated: )
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Custom Reports | <=16.0.0.23040 | |
Schneider-electric Igss Dashboard | <=16.0.0.23040 | |
Schneider-electric Igss Data Server | <=16.0.0.23040 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27983 is a vulnerability that allows deletion of reports from the IGSS project report directory, leading to data loss.
CVE-2023-27983 has a severity level of medium (5.3).
The affected products include Schneider-electric Custom Reports, Schneider-electric Igss Dashboard, and Schneider-electric Igss Data Server.
An attacker can abuse CVE-2023-27983 by deleting reports from the IGSS project report directory, leading to data loss.
Yes, you can find more information about CVE-2023-27983 at the following link: [reference link](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-04.pdf).