CVE-2023-27981

HIGH

Schneider Electric IGSS Data Server & Dashboard < 16.0.0.23040 - RCE via Malicious Report

Title source: llm
STIX 2.1

Description

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

Scores

CVSS v3 7.8
EPSS 0.0073
EPSS Percentile 72.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (3)
schneider-electric/custom_reports < 16.0.0.23040
schneider-electric/igss_dashboard < 16.0.0.23040
schneider-electric/igss_data_server < 16.0.0.23040
Published Mar 21, 2023
Tracked Since Feb 18, 2026