ZDI-CAN-19652: ZDI-23-337: Schneider Electric IGSS IGSSdataServer Exposed Dangerous Function Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19652?
ZDI-CAN-19652 has been classified with a critical severity level due to the potential for arbitrary code execution.
How do I fix ZDI-CAN-19652?
To mitigate ZDI-CAN-19652, it is recommended to apply the latest security patches provided by Schneider Electric for IGSS.
Who is affected by ZDI-CAN-19652?
ZDI-CAN-19652 affects installations of Schneider Electric IGSS, with no authentication requirement to exploit the vulnerability.
Can ZDI-CAN-19652 be exploited remotely?
Yes, ZDI-CAN-19652 allows remote attackers to execute arbitrary code without needing authentication.
What impact does ZDI-CAN-19652 have on my system?
Exploiting ZDI-CAN-19652 can lead to unauthorized access and control over your Schneider Electric IGSS system.