PT-2023-1873 · Unknown · Igss Data Server+2

Published

2023-03-14

·

Updated

2023-03-24

·

CVE-2023-27978

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IGSS Data Server versions 16.0.0.23040 and prior IGSS Dashboard versions 16.0.0.23040 and prior Custom Reports versions 16.0.0.23040 and prior
Description A Deserialization of Untrusted Data issue exists in the Dashboard module, potentially leading to remote code execution when an attacker gets the user to open a malicious file. This could cause an interpretation of malicious payload data. The vulnerability is related to the deserialization of untrusted data, which may allow an attacker to execute arbitrary code in the target system using a specially crafted file.
Recommendations For IGSS Data Server versions 16.0.0.23040 and prior, update to a version later than 16.0.0.23040 to resolve the issue. For IGSS Dashboard versions 16.0.0.23040 and prior, update to a version later than 16.0.0.23040 to resolve the issue. For Custom Reports versions 16.0.0.23040 and prior, update to a version later than 16.0.0.23040 to resolve the issue. As a temporary workaround, consider restricting access to the Dashboard module and avoiding the use of untrusted files until a patch is available.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-01474
CVE-2023-27978
ZDI-23-334

Affected Products

Custom Reports
Igss Dashboard
Igss Data Server