This content is restricted.
Brief
Here is a summary of the provided document:
Summary:
Schneider Electric has released a vulnerability notification for its IGSS (Interactive Graphical SCADA System) product, affecting IGSS Update Service v16.0.0.23211 and prior. The vulnerability, rated CVSS v3 7.8, is a Missing Authentication for Critical Function CWE-306, which could allow a local attacker to change the update source and potentially lead to remote code execution. Schneider Electric has provided an update to address the issue, and users are recommended to apply the patch or implement mitigations such as disabling the IGSS Update Service, reviewing and implementing security guidelines, and following industry cybersecurity best practices. No public exploitation has been reported, and users are advised to take defensive measures to minimize the risk of exploitation.
Highlights content goes here...
This content is restricted.
