A CWE-306: Missing Authentication for Critical Function...
Critical severity
Unreviewed
Published
Feb 12, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Feb 11, 2022
Published to the GitHub Advisory Database
Feb 12, 2022
Last updated
Feb 3, 2023
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)
References