CVE-2020-7479
23.03.2020, 20:15
A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS Update Service.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | interactive_graphical_scada_system | 14.0 ≤ 𝑥 < 14.0.0.20009 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration