VendorsSchneider Electricinteractive_graphical_scada_systemany version
Vulnerabilities

Schneider Electric Interactive Graphical Scada System any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

43CVEs
CVE-2017-9967
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.
Published 2018-02-12 · Modified
7.8EPSS 0.004
CVE-2023-4516
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
Published 2023-09-14 · Modified
7.8EPSS 0.002
CVE-2020-7478
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network when the IGSS Update Service is enabled.
Published 2020-03-23 · Modified
7.5EPSS 0.041
← Prev2 / 2