First published: Thu Mar 16 2023(Updated: )
This vulnerability allows remote attackers to delete application-level data on affected installations of Schneider Electric IGSS. Authentication is not required to exploit this vulnerability.
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric IGSS Dashboard |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-23-340 is considered critical due to the ability for remote attackers to delete application-level data without authentication.
To fix ZDI-23-340, update the affected installation of Schneider Electric IGSS to the latest version provided by the vendor.
ZDI-23-340 allows remote attackers to delete application-level data, potentially causing significant data loss.
No, authentication is not required to exploit ZDI-23-340, making it particularly dangerous.
ZDI-23-340 affects installations of Schneider Electric IGSS, specifically the IGSS Dashboard.