cbcvebase.
CVE-2023-3001
published 2023-06-14

CVE-2023-3001: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data…

PriorityP352high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
31.86%
98.1th percentile
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.

Affected

3 ranges
VendorProductVersion rangeFixed in
msrcwindows_defender_antimalware_platform
schneider-electricigss_dashboard< 16.0.0.2313116.0.0.23131
schneider_electricigss_dashboard

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.