CVE-2023-27984: Input Validation
A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-27984.
What is the severity of CVE-2023-27984?
The severity of CVE-2023-27984 is high.
What is the affected software for CVE-2023-27984?
The affected software for CVE-2023-27984 is Schneider-electric Custom Reports, Schneider-electric Igss Dashboard, and Schneider-electric Igss Data Server, version up to 16.0.0.23040.
What is the CWE ID for CVE-2023-27984?
The CWE ID for CVE-2023-27984 is CWE-20: Improper Input Validation.
How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker planting a malicious report file, which can execute a macro and potentially lead to remote code execution when the file is opened by a user.