PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-27043 Siemens CVE debrief

CVE-2023-27043 is a Python email-module parsing flaw that can cause applications to trust the wrong part of an RFC 2822 header as the addr-spec. In systems that grant access only after confirming an address belongs to an approved domain, this can let a crafted address slip past domain-based signup or verification checks.

Vendor
Siemens
Product
RUGGEDCOM ROX MX5000
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-14
Advisory published
2026-05-12
Advisory updated
2026-05-14

Who should care

Teams running internet-facing Python applications that use the standard library email parser for account creation, email verification, or domain allowlisting should review this immediately. Application security, identity, and platform teams responsible for Python runtime upgrades are also in scope.

Technical summary

The issue is in Python’s email/_parseaddr.py path. When parsing email addresses that contain a special character, the parser can identify the wrong portion of an RFC 2822 header as the addr-spec value. If application logic uses that parsed value to enforce a trusted-domain rule, the validation decision can be wrong and allow an authorization bypass. NVD lists affected Python ranges as 2.7.18; 3.0 through 3.8.19; 3.9.0 through 3.9.19; 3.10.0 through 3.10.14; 3.11.0 through 3.11.9; and 3.12.0 through 3.12.5.

Defensive priority

Medium overall, but high priority for any application that uses Python email parsing as part of authentication, signup gating, or domain-based trust decisions.

Recommended defensive actions

  • Upgrade Python to a version outside the vulnerable ranges listed by NVD, using the fixed release lines in your environment as the target for remediation.
  • Audit code paths that parse email addresses and then make access-control decisions, especially domain allowlists such as @company.example.com signup rules.
  • Avoid relying on the stdlib parser alone for trust decisions; add explicit validation of the canonical email address and domain before granting access.
  • Review existing accounts or signups created through affected workflows for anomalies and re-verify any access decisions that depended on parsed email values.

Evidence notes

This debrief is based on the supplied NVD CVE record, which includes the CVSS vector, affected version ranges, CWE classification, and links to the Python advisory and issue tracker. The publicly described impact is an authorization or validation bypass in applications that depend on email-domain checks; the supplied corpus does not indicate code execution or availability impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-27043 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-27043

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-27043 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-27043

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.