<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T05:31:39.666641+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-01471</id>
    <title>bdu:2023-01471</title>
    <updated>2026-10-08T05:31:39.825923+00:00</updated>
    <content>bdu:2023-01471</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-01471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0218</id>
    <title>certfr-2023-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
    <updated>2026-10-08T05:31:39.825962+00:00</updated>
    <content>certfr-2023-avi-0218</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0218"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-213769</id>
    <title>EUVD-2026-213769</title>
    <updated>2026-10-08T05:31:39.825981+00:00</updated>
    <content>EUVD-2026-213769</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-213769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-27984</id>
    <title>fkie_cve-2023-27984</title>
    <updated>2026-10-08T05:31:39.825994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-27984"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2455-5p2g-hrg7</id>
    <title>GHSA-2455-5p2g-hrg7</title>
    <updated>2026-10-08T05:31:39.826025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2455-5p2g-hrg7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-27984</id>
    <title>gsd-2023-27984</title>
    <updated>2026-10-08T05:31:39.826041+00:00</updated>
    <content>gsd-2023-27984</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-27984"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-082-04</id>
    <title>ICSA-23-082-04 — Schneider Electric IGSS</title>
    <updated>2026-10-08T05:31:39.826051+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability in Schneider Electric Data Server TCP interface could allow the creation of a malicious report file in the IGSS project report directory, and this could lead to remote code execution when an unsuspecting user opens the malicious report.  CVE-2023-27980 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Data Server could cause manipulation of dashboard files in the IGSS project report directory when an attacker sends specific crafted messages to the Data Server TCP port. This could lead to remote code execution if an unsuspecting user opens the malicious dashboard file. CVE-2023-27982 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Dashboard module could cause an interpretation of malicious payload data if a malicious file is opened by an unsuspecting user. This could lead to remote code execution. CVE-2023-27978 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Custom Reports could cause remote code execution if an unsuspecting user opens a malicious report. CVE-2023-27981 has been assigned to this vulnerability. A CVSS v3 base score of…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-082-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sevd-2023-073-04</id>
    <title>SEVD-2023-073-04 — IGSS (Interactive Graphical SCADA System)</title>
    <updated>2026-10-08T05:31:39.826089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Schneider Electric is aware of multiple vulnerabilities in its Data Server, Dashboard and Custom Reports modules for the IGSS (Interactive Graphical SCADA System) product.
The IGSS product is a state-of-the art SCADA system used for monitoring and controlling industrial processes. The Data Server is a module with a TCP interface used by other modules like the Dashboard and the Custom Reports to access data of the SCADA System to be presented.
Failure to apply the remediation provided below may result in Denial of Service and dashboards or report files in the IGSS Report folder being lost, added or changed. Further it may risk remote code execution, which could result in a variety of issues including loss of control of the SCADA System with IGSS running in production mode.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sevd-2023-073-04"/>
  </entry>
</feed>
