CVE-2021-30066 Information
Jun 07, 2022
cve
Description
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23 TCSEFEA23F3F20/21 and Belden Tofino Xenon Security Appliance an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.
CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.belden.com/support/security-assurance https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-05
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
6.8
Share on: