QID 591046

Date Published: 2022-09-20

QID 591046: Schneider Electric IGSS Multiple Vulnrabilities (SEVD-2022-165-01 V2.0)

Schneider Electric is aware of multiple vulnerabilities in its Data Server module for the IGSS (Interactive Graphical SCADA System) product.
IGSS product is a SCADA system used for monitoring and controlling industrial processes. The Data Server is a module with a TCP interface used by other modules to access data of the SCADA System.

affected versions:
IGSS Data Server V15.0.0.22170 and prior
QID Detection Logic:(Authenticated)
It checks for uninstall string in windows registry to fetch the vulnerable version of the product.

successful exploitation can affect confidentiality, integrity, and availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released a patch version to mitigate the vulnerabilities.
    Software Advisories
    Advisory ID Software Component Link
    SEVD-2022-165-01 V2.0 URL Logo urldefense.com/v3/__download.schneider-electric.com/files?p_enDocType=Security*and*Safety*Notice&p_File_Name=SEVD-2022-165-01_IGSS_Security_Notification_V2.pdf&_ga=2.135861433.905451553.1656482445-364830623.1643890284__;Kysr!!Pw1rFClp!or-SZSMi4b_hUSLCdoe8pfPU_7y_PdQJ0BsSQVbhKuqVPof6im4h-VHPNxeNteLMD_gMf6eJgZrueR0gSFQu2dNw$