First published: Thu Sep 14 2023(Updated: )
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
Credit: cybersecurity@se.com cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Interactive Graphical Scada System | <=16.0.0.23211 | |
<=16.0.0.23211 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4516 is a CWE-306: Missing Authentication for Critical Function vulnerability in the IGSS Update Service.
The severity of CVE-2023-4516 is high with a CVSS score of 7.8.
CVE-2023-4516 affects Schneider-electric Interactive Graphical Scada System version 16.0.0.23211 and earlier.
The impact of CVE-2023-4516 is that a local attacker could change the update source and potentially execute remote code by forcing an update with malicious content.
To fix CVE-2023-4516, apply the security update provided by Schneider Electric as mentioned in the security advisory.