ZDI-CAN-19419: ZDI-23-338: Schneider Electric IGSS getRMSreportFile Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19419?
ZDI-CAN-19419 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-CAN-19419?
To mitigate ZDI-CAN-19419, users should ensure that they are using the latest version of Schneider Electric IGSS and follow all vendor security advisories.
What impact does ZDI-CAN-19419 have on my system?
Exploitation of ZDI-CAN-19419 could allow remote attackers to execute arbitrary code on the affected Schneider Electric IGSS installations.
Is user interaction required to exploit ZDI-CAN-19419?
Yes, user interaction is required for ZDI-CAN-19419 as the target must visit a malicious page or open a malicious file.
Who is affected by ZDI-CAN-19419?
ZDI-CAN-19419 affects installations of Schneider Electric IGSS software.