"value":"\nA CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update\nService that could allow a local attacker to change update source, potentially leading to remote\ncode execution when the attacker force an update containing malicious content.\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-306 Missing Authentication for Critical Function",
"cweId":"CWE-306"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Schneider Electric",
"product":{
"product_data":[
{
"product_name":"IGSS Update Service (IGSSupdateservice.exe)",