ZDI-CAN-20793: ZDI-23-889: Schneider Electric IGSS DashFiles Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20793?
The ZDI-CAN-20793 vulnerability has been classified as a high severity issue due to its potential for arbitrary code execution.
How do I fix ZDI-CAN-20793?
To mitigate ZDI-CAN-20793, ensure that your Schneider Electric IGSS software is updated to the latest version provided by the vendor.
What types of attacks can exploit ZDI-CAN-20793?
ZDI-CAN-20793 can be exploited through remote code execution by tricking the user into visiting a malicious page or opening a harmful file.
What user actions are required to exploit ZDI-CAN-20793?
Exploitation of ZDI-CAN-20793 requires user interaction, such as navigating to a malicious web page or opening a compromised file.
Who is affected by ZDI-CAN-20793?
Any installations of Schneider Electric IGSS that have not been updated may be vulnerable to ZDI-CAN-20793.