Schneider Electric IGSS

Summary

Schneider Electric is addressing a vulnerability in the IGSS Definition module of its IGSS SCADA system. This out-of-bounds write vulnerability could lead to data loss or arbitrary code execution if a malicious CGF file is imported, potentially resulting in loss of system control. A patched version, 18.0.0.26125, is available.

IFF Assessment

FOE

The identified vulnerability allows for potential data loss and arbitrary code execution, posing a significant risk to industrial control systems and their operational integrity.

Severity

7.8 High

The CVSS score of 7.8 reflects the severity of an out-of-bounds write vulnerability that could lead to loss of data or arbitrary code execution, with a potential impact on system availability and integrity in critical infrastructure environments.

Defender Context

This alert highlights a critical vulnerability in SCADA systems used in sectors like energy and manufacturing. Defenders should prioritize applying the vendor-provided patch to mitigate risks of data loss and unauthorized code execution. Monitoring for unusual CGF file imports and ensuring system integrity are crucial defense measures.

Read Full Story →