Download of Code Without Integrity Check Vulnerability in Schneider Electric Products
CVE-2023-5984

4.9MEDIUM

Key Information:

Vendor
CVE Published:
15 November 2023

Summary

A vulnerability exists in Schneider Electric's firmware update process, which allows for the possibility of modified firmware being uploaded due to a lack of integrity checks. This flaw could be exploited during an authorized admin's firmware update procedure, potentially leading to unauthorized modifications and security risks. Users of Schneider Electric products should ensure they follow best practices for firmware updates to mitigate potential threats.

Affected Version(s)

ION8650 All versions

ION8800 All versions

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.