The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric IGSS Data Server (IGSSdataServer.exe) version V15.0.0.22139 and prior
- Summary
- A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read specific files in the IGSS project report directory, potentially leading to a denial-of-service condition when an attacker sends specific messages.
- Remediation
- V15.0.0.22171 of IGSS Data Server includes a fix for these vulnerabilities and is available for download through IGSS Master > Update IGSS Software or here: Online IGSS Updates Page: https://igss.schneider-electric.com/licensed-versions/ Direct Download: https://igss.schneider-electric.com/igss/igssupdates/v150/IGSSUPDATE.ZIP
