#VU60570 Path traversal in IGSS Data Server - CVE-2022-24311
Published: February 14, 2022
IGSS Data Server
Schneider Electric
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the IGSSDataServer process. A remote attacker can cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server.