CVE-2023-3001
published 2023-06-14CVE-2023-3001: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data…
PriorityP352high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
31.86%
98.1th percentile
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that
could cause an interpretation of malicious payload data, potentially leading to remote code
execution when an attacker gets the user to open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | windows_defender_antimalware_platform | — | — |
| schneider-electric | igss_dashboard | < 16.0.0.23131 | 16.0.0.23131 |
| schneider_electric | igss_dashboard | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r5pf-h3vv-f4pr: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that
could cause an interpretation of malicious payload data
ghsa_unreviewed·2023-06-14
CVE-2023-3001 [HIGH] CWE-502 GHSA-r5pf-h3vv-f4pr: A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that
could cause an interpretation of malicious payload data
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that
could cause an interpretation of malicious payload data, potentially leading to remote code
execution when an attacker gets the user to open a malicious file.
CISA ICS
Schneider Electric IGSS
cisa_ics·2023-08-08·CVSS 7.8
[HIGH] Schneider Electric IGSS
ICS Advisory
##
Schneider Electric IGSS
Release DateAugust 08, 2023
Alert CodeICSA-23-220-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: low attack complexity
- Vendor: Schneider Electric
- Equipment: IGSS (Interactive Graphical SCADA System)
- Vulnerability: Deserialization of Untrusted Data
## 2. RISK EVALUATION
Successful exploitation of this vulnerability may allow arbitrary code execution or loss of control of the SCADA system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Schneider Electric reports this vulnerability affects the following IGSS (Interactive Graphical SCADA System) products:
-
IGSS Dashboard (DashBoard.exe): v16.0.0.23130 and prior
## 3.2 VULNERABILITY OVERVIEW
3.2.1 DESERIALIZATION OF UNTRUSTED DATA CWE-502
No detection rules found.
No public exploits indexed.
2023-06-14
Published