ZDI-CAN-19531: ZDI-23-340: Schneider Electric IGSSdataServer Exposed Dangerous Function Data Deletion Vulnerability
This vulnerability allows remote attackers to delete application-level data on affected installations of Schneider Electric IGSS. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19531?
The severity of ZDI-CAN-19531 is critical due to the potential for remote data deletion without authentication.
How do I fix ZDI-CAN-19531?
To fix ZDI-CAN-19531, apply the latest security updates provided by Schneider Electric for the IGSS software.
What kind of data can be deleted due to ZDI-CAN-19531?
ZDI-CAN-19531 allows remote attackers to delete application-level data, which could include critical configurations and operational data.
Who is affected by the ZDI-CAN-19531 vulnerability?
All installations of Schneider Electric IGSS are potentially affected by the ZDI-CAN-19531 vulnerability.
Is authentication required to exploit ZDI-CAN-19531?
No, authentication is not required to exploit the ZDI-CAN-19531 vulnerability, making it particularly dangerous.