CVE-2023-45853
View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing fur...
Affects 2 products across 3 vendors.
Arithmetic operation exceeds the maximum integer value, wrapping around and often leading to undersized allocations.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2023-45853 affects MiniZip in zlib versions up to 1.3, leading to an integer overflow and heap-based buffer overflow when handling long filenames, comments, or extra fields. This vulnerability has a CVSS score of 9.8, indicating a critical severity level. Affected vendors include Fujitsu-Siemens, Siemens, Smihica, and Zlib. No public proof of concept or known exploits exist, and the EPSS score is low, suggesting a minimal likelihood of exploitation in the wild. However, due to the critical nature of the vulnerability, immediate action is recommended to mitigate potential risks in ICS/OT environments.
BSID: BS-2023-GLOBAL-055283-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2023-45853?
What is the CVSS score for CVE-2023-45853?
Is CVE-2023-45853 actively exploited?
How do I remediate CVE-2023-45853?
What systems are affected by CVE-2023-45853?
What NERC-CIP standard applies to CVE-2023-45853?
What IEC 62443 requirement maps to CVE-2023-45853?
| CVE ID | CVE-2023-45853 |
|---|---|
| BSID | BS-2023-GLOBAL-055283-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2026-07-21 |
| Last Modified | 2026-07-21 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available. The following versions of Siemens CADRA are affected: CADRA vers:intdot/<2511, vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.8 Siemens Siemens CADRA Improper Input Validation, Incor
Source: NIST NVD / MITRE CVE Database
The vulnerability can be exploited remotely without authentication, requiring only network access to the affected system. An attacker can trigger the integer overflow and heap-based buffer overflow by providing a specially crafted long filename, comment, or extra field during the creation of a new file in a ZIP archive. This can lead to arbitrary code execution, potentially allowing the attacker to gain control of the affected system.
Exploitation Likelihood: MINIMAL
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement network segmentation and access controls to limit exposure to untrusted sources. Monitor network traffic for suspicious activity related to ZIP file creation and manipulation.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it allows unauthorized access to and control of electronic security perimeters, which can compromise the security of critical cyber assets.
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to cause a denial of service or unauthorized access, which can impact the availability and integrity of industrial control systems.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 47a2a0e925d08ff12461f7e6a40b2f4033769bb424d9fdee39f5f693d610f3f5a845c1d55b2ece81413c3a71decd9da65bb44cc30f20f3b187a2cd3862134be5 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →