CVE-2021-30064: Critical severity belden tofino xenon security appliance firmware vulnerability
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-30064?
CVE-2021-30064 is a vulnerability found in Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance that allows SSH login with hardcoded default credentials.
How severe is CVE-2021-30064?
CVE-2021-30064 has a severity rating of 9.8, which is considered critical.
What software is affected by CVE-2021-30064?
CVE-2021-30064 affects Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance.
Are there any known fixes for CVE-2021-30064?
Yes, Schneider Electric has released a firmware update to address the vulnerability. It is recommended to update to version 03.23 or later.
Where can I find more information about CVE-2021-30064?
You can find more information about CVE-2021-30064 on Schneider Electric's security advisory page (SEVD-2022-011-05) and Belden's support page.