Rewterz Threat Alert – Chaos Ransomware – Active IOCs
March 17, 2023Rewterz Threat Advisory – ICS: Rockwell Automation Modbus TCP AOI Server Vulnerability
March 19, 2023Rewterz Threat Alert – Chaos Ransomware – Active IOCs
March 17, 2023Rewterz Threat Advisory – ICS: Rockwell Automation Modbus TCP AOI Server Vulnerability
March 19, 2023Severity
High
Analysis Summary
CVE-2023-27984 CVSS:7.8
Schneider Electric IGSS could allow a remote attacker to execute arbitrary code on the system, caused by improper input validation by the openReport function. By persuading a victim to open a specially crafted report file, an attacker could exploit this vulnerability to execute arbitrary code in the context of the current user.
CVE-2023-27983 CVSS:6.5
Schneider Electric IGSS could allow a remote attacker to bypass security restrictions, caused by a flaw in IGSSdataServer process. By sending a specially crafted request, an attacker could exploit this vulnerability to delete reports from the IGSS project report directory.
CVE-2023-27982 CVSS:8.1
Schneider Electric IGSS could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the IGSSdataServer process. By sending specially crafted messages to the Data Server TCP port, an attacker could exploit this vulnerability to execute arbitrary code in the context of the current user.
CVE-2023-27981 CVSS:7.8
Schneider Electric IGSS could allow a remote attacker to traverse directories on the system, caused by improper validation of user request by the getRMSreportFile function. An attacker could send a specially crafted URL request containing “dot dot” sequences (/../) to execute code in the context of the current user.
CVE-2023-27980 CVSS:8.8
Schneider Electric IGSS could allow a remote attacker to execute arbitrary code on the system, caused by a flaw in the IGSSdataServer process. By persuading a victim to open a specially crafted report, an attacker could exploit this vulnerability to execute arbitrary code in the context of the current user.
CVE-2023-27979 CVSS:6.5
Schneider Electric IGSS is vulnerable to a denial of service, caused by a flaw in the IGSSdataServer process. By sending specially crafted messages to the Data Server TCP port, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2023-27978 CVSS:4.4
Schneider Electric IGSS could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization in the DashFiles class. By persuading a victim to open specially crafted report, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2023-27977 CVSS:6.5
Schneider Electric IGSS is vulnerable to a denial of service, caused by a flaw in the IGSSdataServer process. By sending specially crafted messages to the Data Server TCP port, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Impact
- Code Execution
- Denial of Service
- Security Bypass
Indicators Of Compromise
CVE
- CVE-2023-27984
- CVE-2023-27983
- CVE-2023-27982
- CVE-2023-27981
- CVE-2023-27980
- CVE-2023-27979
- CVE-2023-27978
- CVE-2023-27977
Affected Vendors
Schneider Electric
Affected Products
- Schneider Electric IGSS Data Server 16.0.0.23040
- Schneider Electric IGSS Dashboard 16.0.0.23040
- Schneider Electric IGSS Custom Reports 16.0.0.23040
Remediation
Refer to Schneider Electric Security Advisory for patch, upgrade or suggested workaround information.