Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2pq-xrmc-f4r4

Опубликовано: 05 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

EPSS

Процентиль: 0%
0.00004
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.8
nvd
почти 4 года назад

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

CVSS3: 6.8
fstec
около 4 лет назад

Уязвимость межсетевых экранов Tofino Xenon Security Appliance, Tofino Argon Security Appliance и EAGLE 20 Tofino, связанная с обходом проверки криптографической подписи на USB-накопителе, позволяющая нарушителю загрузить произвольный образ встроенного программного обеспечения

EPSS

Процентиль: 0%
0.00004
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-347