CVE-2022-32528

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
30/01/2023
Last modified:
16/05/2023

Description

<br /> A CWE-306: Missing Authentication for Critical Function vulnerability exists that could<br /> cause access to manipulate and read specific files in the IGSS project report directory,<br /> potentially leading to a denial-of-service condition when an attacker sends specific messages.<br /> <br /> Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:*:*:*:*:*:*:*:* 15.0.0.22170 (including)