Schneider.Electric.IGSS.IGSSupdateservice.Directory.Traversal
Description
This indicates an attack attempt to exploit a Directory Traversal Vulnerability in Schneider Electric IGSS.
The vulnerability is due to improper handling of a user-supplied path in IGSSupdateservice service. A remote unauthenticated attacker could exploit this vulnerability by sending a crafted request to the target server. Successful exploitation in the worst case could lead to disclose arbitrary file content in the context of SYSTEM.
Affected Products
Schneider Electric IGSS prior to 14.0.0.20009
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://www.se.com/ww/en/download/document/SEVD-2020-070-01/
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2020-05-06 | 15.838 | Default_action:pass:drop |
2020-05-06 | 15.837 | Default_action:drop:pass |
2020-05-06 | 15.836 | Default_action:pass:drop |
2020-04-27 | 15.828 |