ZDI-23-338: Schneider Electric IGSS getRMSreportFile Directory Traversal Remote Code Execution Vulnerability
Published Mar 16, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Schneider Electric IGSS
Event History
Mar 16, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-338?
The severity of ZDI-23-338 is critical due to its potential for remote code execution.
2
How do I fix ZDI-23-338?
To fix ZDI-23-338, update Schneider Electric IGSS to the latest version provided by the vendor.
3
What impact does ZDI-23-338 have on Schneider Electric IGSS?
ZDI-23-338 allows remote attackers to execute arbitrary code, compromising the security of the affected system.
4
Is user interaction required to exploit ZDI-23-338?
Yes, user interaction is required for ZDI-23-338; the target must visit a malicious page or open a malicious file.
5
What systems are affected by ZDI-23-338?
ZDI-23-338 affects installations of Schneider Electric IGSS.