Vulnerabilities > CVE-2023-3001 - Deserialization of Untrusted Data vulnerability in Schneider-Electric Igss Dashboard 16.0.0.23040/16.0.0.23130
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |