PatchSiren cyber security CVE debrief
CVE-2023-27043 Siemens CVE debrief
CVE-2023-27043 is a Python email-module parsing flaw that can cause applications to trust the wrong part of an RFC 2822 header as the addr-spec. In systems that grant access only after confirming an address belongs to an approved domain, this can let a crafted address slip past domain-based signup or verification checks.
- Vendor
- Siemens
- Product
- RUGGEDCOM ROX MX5000
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-14
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-14
Who should care
Teams running internet-facing Python applications that use the standard library email parser for account creation, email verification, or domain allowlisting should review this immediately. Application security, identity, and platform teams responsible for Python runtime upgrades are also in scope.
Technical summary
The issue is in Python’s email/_parseaddr.py path. When parsing email addresses that contain a special character, the parser can identify the wrong portion of an RFC 2822 header as the addr-spec value. If application logic uses that parsed value to enforce a trusted-domain rule, the validation decision can be wrong and allow an authorization bypass. NVD lists affected Python ranges as 2.7.18; 3.0 through 3.8.19; 3.9.0 through 3.9.19; 3.10.0 through 3.10.14; 3.11.0 through 3.11.9; and 3.12.0 through 3.12.5.
Defensive priority
Medium overall, but high priority for any application that uses Python email parsing as part of authentication, signup gating, or domain-based trust decisions.
Recommended defensive actions
- Upgrade Python to a version outside the vulnerable ranges listed by NVD, using the fixed release lines in your environment as the target for remediation.
- Audit code paths that parse email addresses and then make access-control decisions, especially domain allowlists such as @company.example.com signup rules.
- Avoid relying on the stdlib parser alone for trust decisions; add explicit validation of the canonical email address and domain before granting access.
- Review existing accounts or signups created through affected workflows for anomalies and re-verify any access decisions that depended on parsed email values.
Evidence notes
This debrief is based on the supplied NVD CVE record, which includes the CVSS vector, affected version ranges, CWE classification, and links to the Python advisory and issue tracker. The publicly described impact is an authorization or validation bypass in applications that depend on email-domain checks; the supplied corpus does not indicate code execution or availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-27043 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-27043
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-27043 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-27043
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-577017.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-577017.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.