Schneider Electric IGSS
Summary
Schneider Electric is addressing a vulnerability in the IGSS Definition module of its IGSS SCADA system. This out-of-bounds write vulnerability could lead to data loss or arbitrary code execution if a malicious CGF file is imported, potentially resulting in loss of system control. A patched version, 18.0.0.26125, is available.
IFF Assessment
The identified vulnerability allows for potential data loss and arbitrary code execution, posing a significant risk to industrial control systems and their operational integrity.
Severity
The CVSS score of 7.8 reflects the severity of an out-of-bounds write vulnerability that could lead to loss of data or arbitrary code execution, with a potential impact on system availability and integrity in critical infrastructure environments.
Defender Context
This alert highlights a critical vulnerability in SCADA systems used in sectors like energy and manufacturing. Defenders should prioritize applying the vendor-provided patch to mitigate risks of data loss and unauthorized code execution. Monitoring for unusual CGF file imports and ensuring system integrity are crucial defense measures.