CVE-2023-27980 - Schneider-electric Custom Reports, Schneider-electric Igss Dashboard and Schneider-electric Igss Data Server

Critical 8.8

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior)

Affected software

Schneider-electric Custom Reports

Schneider-electric Igss Dashboard

Schneider-electric Igss Data Server

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.