Improper Validation of Array Index in Foxboro Driver by Schneider Electric
CVE-2023-2570

7.8HIGH

Key Information:

Vendor
CVE Published:
14 June 2023

Summary

An improper validation of array index vulnerability has been identified in the Foxboro.sys driver, which could allow a local user to exploit the issue. By crafting a specially designed script or program that manipulates an unpredictable index in an IOCTL call, an attacker may cause local denial-of-service conditions and potentially execute arbitrary code in the kernel space. This vulnerability exposes the impacted systems to significant risks, making it essential for users to apply the necessary updates and mitigate potential threats.

Affected Version(s)

EcoStruxure Foxboro DCS Control Core Services All versions prior to patch HF9857795

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.