SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-3001

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.

HIGH 7.8EPSS 31.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 31.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
31.86% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-502
Affected
schneider-electric/igss dashboard
Source
cybersecurity@se.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.