QID 591051

Date Published: 2022-09-28

QID 591051: Schneider Electric IGSS Multiple Vulnrabilities (SEVD-2022-102-01 V2.0)

Schneider Electric is aware of multiple vulnerabilities in its Data Server module for the IGSS (Interactive Graphical SCADA System) product.
IGSS product is a SCADA system used for monitoring and controlling industrial processes. The Data Server is a module with a TCP interface used by other modules to access data of the SCADA System.

affected versions:
IGSS Data Server V15.0.0.22170 and prior
QID Detection Logic:(Authenticated)
It checks for uninstall string in windows registry to fetch the vulnerable version of the product.

successful exploitation can affect confidentiality, integrity, and availability.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released a patch version to mitigate the vulnerabilities.

    CVEs related to QID 591051

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2022-102-01 V2.0 URL Logo download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-102-01_IGSS_Security_Notification_V2.0.pdf&p_Doc_Ref=SEVD-2022-102-01&_ga=2.84367067.379817086.1657688302-364830623.1643890284 [download.schneider-electric.com]