Rewterz
Rewterz Threat Alert – RedLine Stealer – Active IOCs
October 15, 2023
Rewterz
Rewterz Threat Advisory – Multiple IBM Security Verify Access Vulnerabilities
October 16, 2023

Rewterz Threat Advisory – ICS: Schneider Electric IGSS Update Service Vulnerability

Severity

High

Analysis Summary

CVE-2023-4516

A missing authentication for critical function vulnerability that could allow a local attacker to change the update source exists in the IGSS Update Service, which could lead to remote code execution the attacker force an update containing malicious content.

Impact

  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2023-4516

Affected Vendors

Schneider Electric

Affected Products

  • Schneider Electric IGSS Update Service 16.0.0.23211

Remediation

Refer to Schneider Electric for patch, upgrade or suggested workaround information. 

Schneider Electric