PT-2023-1870 · Unknown · Igss Data Server+2

CVE-2023-27979

·

Publicado

2023-03-14

·

Atualizado

2023-05-24

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions IGSS Data Server versions V16.0.0.23040 and prior IGSS Dashboard versions V16.0.0.23040 and prior Custom Reports versions V16.0.0.23040 and prior
Description The issue is related to insufficient verification of data authenticity, which could allow a remote attacker to cause a denial of service by sending specially crafted messages to the Data Server TCP port. This vulnerability may enable the renaming of files in the IGSS project report directory.
Recommendations For IGSS Data Server version V16.0.0.23040 and prior, consider disabling the IGSSdataServer.exe service until a patch is available to prevent exploitation. For IGSS Dashboard version V16.0.0.23040 and prior, restrict access to the DashBoard.exe executable to minimize the risk of exploitation. For Custom Reports version V16.0.0.23040 and prior, avoid using the RMS16.dll module until the issue is resolved. As a temporary workaround, consider blocking specific crafted messages to the Data Server TCP port to prevent denial of service.

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01470
CVE-2023-27979
ZDI-23-336

Produtos afetados

Custom Reports
Igss Dashboard
Igss Data Server