cve/2023/CVE-2023-3001.md

18 lines
820 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-3001](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3001)
![](https://img.shields.io/static/v1?label=Product&message=IGSS%20Dashboard%20(DashBoard.exe)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20v16.0.0.23130%20and%20prior%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-502%20Deserialization%20of%20Untrusted%20Data&color=brighgreen)
### Description
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module thatcould cause an interpretation of malicious payload data, potentially leading to remote codeexecution when an attacker gets the user to open a malicious file.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds