ZDI-23-340: Schneider Electric IGSSdataServer Exposed Dangerous Function Data Deletion Vulnerability
This vulnerability allows remote attackers to delete application-level data on affected installations of Schneider Electric IGSS. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-340?
The severity of ZDI-23-340 is considered critical due to the ability for remote attackers to delete application-level data without authentication.
How do I fix ZDI-23-340?
To fix ZDI-23-340, update the affected installation of Schneider Electric IGSS to the latest version provided by the vendor.
What types of data can be affected by ZDI-23-340?
ZDI-23-340 allows remote attackers to delete application-level data, potentially causing significant data loss.
Is authentication required to exploit ZDI-23-340?
No, authentication is not required to exploit ZDI-23-340, making it particularly dangerous.
Which software is affected by ZDI-23-340?
ZDI-23-340 affects installations of Schneider Electric IGSS, specifically the IGSS Dashboard.