ZDI-23-337: Schneider Electric IGSS IGSSdataServer Exposed Dangerous Function Remote Code Execution Vulnerability
Published Mar 16, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Schneider Electric IGSS
Event History
Mar 16, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-337?
The severity of ZDI-23-337 is critical due to the potential for remote code execution without authentication.
2
How do I fix ZDI-23-337?
To fix ZDI-23-337, apply the latest security updates provided by Schneider Electric for IGSS.
3
What types of attacks can exploit ZDI-23-337?
ZDI-23-337 can be exploited by remote attackers to execute arbitrary code on vulnerable installations.
4
Is authentication required to exploit ZDI-23-337?
No, authentication is not required to exploit the ZDI-23-337 vulnerability.
5
Which software versions are affected by ZDI-23-337?
ZDI-23-337 affects installations of Schneider Electric IGSS without specifying a version.