ZDI-CAN-19533: ZDI-23-339: Schneider Electric IGSS IGSSdataServer Exposed Dangerous Function Remote Code Execution Vulnerability
Published Mar 16, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Schneider Electric IGSS
Event History
Mar 16, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19533?
ZDI-CAN-19533 has a critical severity rating due to the potential for remote code execution without authentication.
2
How do I fix ZDI-CAN-19533?
To address ZDI-CAN-19533, update Schneider Electric IGSS to the latest secure version provided by the vendor.
3
Who is affected by ZDI-CAN-19533?
ZDI-CAN-19533 affects installations of Schneider Electric IGSS across all versions.
4
Can ZDI-CAN-19533 be exploited remotely?
Yes, ZDI-CAN-19533 allows remote attackers to execute arbitrary code without needing authentication.
5
What impact can ZDI-CAN-19533 have on my system?
Exploitation of ZDI-CAN-19533 can lead to unauthorized control over the affected Schneider Electric IGSS installations.