CVE-2023-4516

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
14/09/2023
Last modified:
20/09/2023

Description

<br /> A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update<br /> Service that could allow a local attacker to change update source, potentially leading to remote<br /> code execution when the attacker force an update containing malicious content.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:*:*:*:*:*:*:*:* 16.0.0.23211 (including)