8.8

CVE-2023-29410

A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated
attacker to gain the same privilege as the application on the server when a malicious payload is
provided over HTTP for the server to execute. 

 



Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Insighthome Firmware Version 1.16 Update -
   Schneider-electric ≫ Insighthome Version -
Schneider-electric ≫ Insighthome Firmware Version 1.16 Update build_004
   Schneider-electric ≫ Insighthome Version -
Schneider-electric ≫ Insightfacility Firmware Version 1.16 Update -
   Schneider-electric ≫ Insightfacility Version -
Schneider-electric ≫ Insightfacility Firmware Version 1.16 Update build_004
   Schneider-electric ≫ Insightfacility Version -
Schneider-electric ≫ Conext Gateway Firmware Version 1.16 Update -
   Schneider-electric ≫ Conext Gateway Version -
Schneider-electric ≫ Conext Gateway Firmware Version 1.16 Update build_004
   Schneider-electric ≫ Conext Gateway Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.66% 0.467
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SE.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-101-02.pdf
Patch
Vendor Advisory