IGSS (Interactive Graphical SCADA System)
Schneider Electric IGSS Data Server contains multiple vulnerabilities in its TCP interface that allow unauthenticated remote access. These flaws (CWE-306 missing authentication, CWE-120 buffer overflow) could enable remote code execution, unauthorized data modification or deletion in the Report folder, and denial of service. The Data Server is a core component used by other IGSS modules to access and manage SCADA system data. Successful exploitation in production mode could result in loss of process control and disclosure of sensitive operational data.
- Network access to IGSS Data Server TCP port
- No authentication credentials required
- IGSS Data Server version 15.0.0.22170 or earlier running
Patching may require device reboot — plan for process interruption
/api/v1/advisories/0b526e6c-e196-4b20-a4ff-fcd9bf1dd725Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.