CVE-2023-3001

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:igss_dashboard:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:16

Type Values Removed Values Added
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-164-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-164-02.pdf - Vendor Advisory () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-164-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-164-02.pdf - Vendor Advisory

21 Jun 2023, 21:06

Type Values Removed Values Added
First Time Schneider-electric igss Dashboard
Schneider-electric
CPE cpe:2.3:a:schneider-electric:igss_dashboard:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-164-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-164-02.pdf - (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-164-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-164-02.pdf - Vendor Advisory

14 Jun 2023, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-14 08:15

Updated : 2024-11-21 08:16


NVD link : CVE-2023-3001

Mitre link : CVE-2023-3001

CVE.ORG link : CVE-2023-3001


JSON object : View

Products Affected

schneider-electric

  • igss_dashboard
CWE
CWE-502

Deserialization of Untrusted Data