ZDI-23-334: Schneider Electric IGSS DashFiles Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Mar 16, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Schneider Electric IGSS
Event History
Mar 16, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-334?
ZDI-23-334 has a critical severity rating due to the potential for remote code execution.
2
How do I fix ZDI-23-334?
To mitigate ZDI-23-334, update Schneider Electric IGSS to the latest version that addresses this vulnerability.
3
What type of exploitation is possible with ZDI-23-334?
ZDI-23-334 allows remote attackers to execute arbitrary code by enticing users to visit a malicious page or open a malicious file.
4
What users are affected by ZDI-23-334?
Users of Schneider Electric IGSS are affected by ZDI-23-334.
5
Is user interaction required to exploit ZDI-23-334?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.