« Volver al listado

CVE-2023-5391

Estado: ModificadaCrítica (9.8)—

A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5391",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-5391",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-26T21:50:43.582116Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@se.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@se.com",
      "affectedData": [
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Monitoring Expert",
          "versions": [
            {
              "status": "affected",
              "version": "All versions – prior to application of Hotfix-145271"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Operation (EPO) with Advanced Reports",
          "versions": [
            {
              "status": "affected",
              "version": "All versions – prior to application of Hotfix-145271"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power SCADA Operation with Advanced Reports",
          "versions": [
            {
              "status": "affected",
              "version": "All versions – prior to application of Hotfix-145271"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-04T19:15:10.777",
  "references": [
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-283-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-283-02.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cybersecurity@se.com"
    },
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-283-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-283-02.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@se.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\n\n\nA CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to\nexecute arbitrary code on the targeted system by sending a specifically crafted packet to the\napplication.\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "CWE-502: Existe una vulnerabilidad deserialización de datos no confiables que podría permitir a un atacante ejecutar código arbitrario en el sistema objetivo enviando un paquete específicamente manipulado a la aplicación."
    }
  ],
  "lastModified": "2026-06-17T06:48:29.860",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B682ECD9-985F-4906-B936-DD388165063A"
            },
            {
              "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_power_operation_with_advanced_reports:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A9E16D1-278E-4E0B-A604-13096B7A9029"
            },
            {
              "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_power_scada_operation_with_advanced_reports:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC4A71CF-78EA-43F9-B7BA-9ED3C7816173"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cybersecurity@se.com"
}