Download of Code Without Integrity Check Vulnerability in Schneider Electric Products
CVE-2023-5984
4.9MEDIUM
Summary
A vulnerability exists in Schneider Electric's firmware update process, which allows for the possibility of modified firmware being uploaded due to a lack of integrity checks. This flaw could be exploited during an authorized admin's firmware update procedure, potentially leading to unauthorized modifications and security risks. Users of Schneider Electric products should ensure they follow best practices for firmware updates to mitigate potential threats.
Affected Version(s)
ION8650 All versions
ION8800 All versions
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved