QID 591051
Date Published: 2022-09-28
QID 591051: Schneider Electric IGSS Multiple Vulnrabilities (SEVD-2022-102-01 V2.0)
Schneider Electric is aware of multiple vulnerabilities in its Data Server module for the IGSS (Interactive Graphical SCADA System) product.
IGSS product is a SCADA system used for monitoring and controlling industrial processes. The Data Server is a module with a TCP interface used by other modules to access data of the SCADA System.
affected versions:
IGSS Data Server V15.0.0.22170 and prior
QID Detection Logic:(Authenticated)
It checks for uninstall string in windows registry to fetch the vulnerable version of the product.
successful exploitation can affect confidentiality, integrity, and availability.
Solution
The vendor has released a patch version to mitigate the vulnerabilities.
Vendor References
CVEs related to QID 591051
Software Advisories