<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 09:36:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-01473</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01473</link>
      <description>bdu:2023-01473</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01473</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0218 — De multiples vulnérabilités ont été découvertes dans les produits
Schneider Electric. Certaines d'entre elles permetten…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0218</link>
      <description>certfr-2023-avi-0218</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0218</guid>
    </item>
    <item>
      <title>EUVD-2026-213776</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-213776</link>
      <description>EUVD-2026-213776</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-213776</guid>
    </item>
    <item>
      <title>fkie_cve-2023-27977</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-27977</link>
      <description>&lt;p&gt;A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-27977</guid>
    </item>
    <item>
      <title>GHSA-8c9m-95jr-9f2r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8c9m-95jr-9f2r</link>
      <description>&lt;p&gt;A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8c9m-95jr-9f2r</guid>
    </item>
    <item>
      <title>gsd-2023-27977</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-27977</link>
      <description>gsd-2023-27977</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-27977</guid>
    </item>
    <item>
      <title>ICSA-23-082-04 — Schneider Electric IGSS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-082-04</link>
      <description>&lt;p&gt;A vulnerability in Schneider Electric Data Server TCP interface could allow the creation of a malicious report file in the IGSS project report directory, and this could lead to remote code execution when an unsuspecting user opens the malicious report.  CVE-2023-27980 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Data Server could cause manipulation of dashboard files in the IGSS project report directory when an attacker sends specific crafted messages to the Data Server TCP port. This could lead to remote code execution if an unsuspecting user opens the malicious dashboard file. CVE-2023-27982 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Dashboard module could cause an interpretation of malicious payload data if a malicious file is opened by an unsuspecting user. This could lead to remote code execution. CVE-2023-27978 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Custom Reports could cause remote code execution if an unsuspecting user opens a malicious report. CVE-2023-27981 has been assigned to this vulnerability. A CVSS v3 base score of…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in Schneider Electric Data Server TCP interface could allow the creation of a malicious report file in the IGSS project report directory, and this could lead to remote code execution when an unsuspecting user opens the malicious report.  CVE-2023-27980 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Data Server could cause manipulation of dashboard files in the IGSS project report directory when an attacker sends specific crafted messages to the Data Server TCP port. This could lead to remote code execution if an unsuspecting user opens the malicious dashboard file. CVE-2023-27982 has been assigned to this vulnerability. A CVSS v3 base score of 8.8 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Dashboard module could cause an interpretation of malicious payload data if a malicious file is opened by an unsuspecting user. This could lead to remote code execution. CVE-2023-27978 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). A vulnerability in Schneider Electric Custom Reports could cause remote code execution if an unsuspecting user opens a malicious report. CVE-2023-27981 has been assigned to this vulnerability. A CVSS v3 base score of…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-082-04</guid>
    </item>
    <item>
      <title>SEVD-2023-073-04 — IGSS (Interactive Graphical SCADA System)</title>
      <link>https://cve.radiocsirt.org/vuln/sevd-2023-073-04</link>
      <description>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its Data Server, Dashboard and Custom Reports modules for the IGSS (Interactive Graphical SCADA System) product.&#13;
The IGSS product is a state-of-the art SCADA system used for monitoring and controlling industrial processes. The Data Server is a module with a TCP interface used by other modules like the Dashboard and the Custom Reports to access data of the SCADA System to be presented.&#13;
Failure to apply the remediation provided below may result in Denial of Service and dashboards or report files in the IGSS Report folder being lost, added or changed. Further it may risk remote code execution, which could result in a variety of issues including loss of control of the SCADA System with IGSS running in production mode.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Schneider Electric is aware of multiple vulnerabilities in its Data Server, Dashboard and Custom Reports modules for the IGSS (Interactive Graphical SCADA System) product.&#13;
The IGSS product is a state-of-the art SCADA system used for monitoring and controlling industrial processes. The Data Server is a module with a TCP interface used by other modules like the Dashboard and the Custom Reports to access data of the SCADA System to be presented.&#13;
Failure to apply the remediation provided below may result in Denial of Service and dashboards or report files in the IGSS Report folder being lost, added or changed. Further it may risk remote code execution, which could result in a variety of issues including loss of control of the SCADA System with IGSS running in production mode.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sevd-2023-073-04</guid>
    </item>
  </channel>
</rss>
