← Back to home
ICSA-20-324-04  ·  Published 2020-11-17  ·  View on CISA ICS-CERT ↗

Schneider Electric Interactive Graphical SCADA System (IGSS)

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities may result in remote code execution.

Remediations

  • Schneider Electric has provided a new version of the IGSS Definition module to address these vulnerabilities. Users are recommended to update to IGSS Version 14.0.0.20248
  • Avoid importing CGF files from untrusted sources
  • Users should also consider upgrading to the latest product offering IGSS v15 to resolve this issue.
  • For more information, see Schneider Electric security notification SEVD-2020-315-03

Affected Vendors

Schneider Electric Software, LLC

Affected Products (1)

Schneider Electric Software, LLC · IGSS Definition (Def.exe) <= 14.0.0.20247

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more