Improper Validation of Array Index in Foxboro Driver by Schneider Electric
CVE-2023-2570
7.8HIGH
Summary
An improper validation of array index vulnerability has been identified in the Foxboro.sys driver, which could allow a local user to exploit the issue. By crafting a specially designed script or program that manipulates an unpredictable index in an IOCTL call, an attacker may cause local denial-of-service conditions and potentially execute arbitrary code in the kernel space. This vulnerability exposes the impacted systems to significant risks, making it essential for users to apply the necessary updates and mitigate potential threats.
Affected Version(s)
EcoStruxure Foxboro DCS Control Core Services All versions prior to patch HF9857795
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database