---
cve: "CVE-2023-27982"
severity: "HIGH"
cvss: 8.8
epss: "40%"
vendor: "Schneider Electric"
kev: false
exploited: false
published: "2023-03-21 07:15:08"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T02:40:47+02:00"
---

# CVE-2023-27982

> 8.8 HIGH

## Beschreibung

A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim eventually opens a malicious dashboard file. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior).

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-345** — Insufficient Verification of Data Authenticity
  The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

## Angriffsmuster (CAPEC)

- [CAPEC-111 — JSON Hijacking (aka JavaScript Hijacking)](https://capec.mitre.org/data/definitions/111.html) _(Severity: High)_
- [CAPEC-141 — Cache Poisoning](https://capec.mitre.org/data/definitions/141.html) _(Severity: High)_
- [CAPEC-142 — DNS Cache Poisoning](https://capec.mitre.org/data/definitions/142.html) _(Severity: High)_
- [CAPEC-148 — Content Spoofing](https://capec.mitre.org/data/definitions/148.html) _(Severity: Medium)_
- [CAPEC-218 — Spoofing of UDDI/ebXML Messages](https://capec.mitre.org/data/definitions/218.html) _(Severity: Medium)_
- [CAPEC-384 — Application API Message Manipulation via Man-in-the-Middle](https://capec.mitre.org/data/definitions/384.html) _(Severity: Low)_
- [CAPEC-385 — Transaction or Event Tampering via Application API Manipulation](https://capec.mitre.org/data/definitions/385.html) _(Severity: Medium)_
- [CAPEC-386 — Application API Navigation Remapping](https://capec.mitre.org/data/definitions/386.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1557.002 — Adversary-in-the-Middle: ARP Cache Poisoning](https://attack.mitre.org/techniques/T1557/002/)
- [T1584.002 — Compromise Infrastructure: DNS Server](https://attack.mitre.org/techniques/T1584/002/)
- [T1491 — Defacement](https://attack.mitre.org/techniques/T1491/)

## Referenzen

- <https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-04.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-27982) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
