Improper Validation of Array Index in Foxboro Driver by Schneider Electric
CVE-2023-2570
7.8HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 14 June 2023
What is CVE-2023-2570?
An improper validation of array index vulnerability has been identified in the Foxboro.sys driver, which could allow a local user to exploit the issue. By crafting a specially designed script or program that manipulates an unpredictable index in an IOCTL call, an attacker may cause local denial-of-service conditions and potentially execute arbitrary code in the kernel space. This vulnerability exposes the impacted systems to significant risks, making it essential for users to apply the necessary updates and mitigate potential threats.
Affected Version(s)
EcoStruxure Foxboro DCS Control Core Services All versions prior to patch HF9857795