8.8
CVE-2023-29410
- EPSS 0.66%
- Veröffentlicht 18.04.2023 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:57:00
- Erkennungen
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Insighthome Firmware Version < 1.16
Schneider-electric ≫ Insighthome Firmware Version 1.16 Update -
Schneider-electric ≫ Insighthome Firmware Version 1.16 Update build_004
Schneider-electric ≫ Insightfacility Firmware Version < 1.16
Schneider-electric ≫ Insightfacility Firmware Version 1.16 Update -
Schneider-electric ≫ Insightfacility Firmware Version 1.16 Update build_004
Schneider-electric ≫ Conext Gateway Firmware Version < 1.16
Schneider-electric ≫ Conext Gateway Firmware Version 1.16 Update -
Schneider-electric ≫ Conext Gateway Firmware Version 1.16 Update build_004
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.467 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| SE.com | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-02.pdf