Vulnerability Details CVE-2023-4516
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update
Service that could allow a local attacker to change update source, potentially leading to remote
code execution when the attacker force an update containing malicious content.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.9%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-4516
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:10.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:12.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:13.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:13.0.0.19140
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0.0.19120
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0.0.20009
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:14.0.0.20247
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:15.0.0.22074
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:16.0.0.23211
-
cpe:2.3:a:schneider-electric:interactive_graphical_scada_system:9.0