CVE-2023-27983

MEDIUM

Schneider Electric IGSS < 16.0.0.23040 - Unauthenticated Report Deletion via TCP

Title source: llm
STIX 2.1

Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 40.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
schneider-electric/custom_reports < 16.0.0.23040
schneider-electric/igss_dashboard < 16.0.0.23040
schneider-electric/igss_data_server < 16.0.0.23040
Published Mar 21, 2023
Tracked Since Feb 18, 2026