First published: Sun Apr 03 2022(Updated: )
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Belden Tofino Xenon Security Appliance Firmware | <03.2.03 | |
Belden Tofino Xenon Security Appliance Firmware | ||
Belden Tofino Argon Fa-tsa-220-tx/mm Firmware | ||
Belden Tofino Argon Fa-tsa-220-tx/mm | ||
Belden Tofino Argon Fa-tsa-220-tx/tx Firmware | ||
Belden Tofino Argon Fa-tsa-220-tx/tx | ||
Belden Tofino Argon Fa-tsa-220-mm/tx Firmware | ||
Belden Tofino Argon Fa-tsa-220-mm/tx | ||
Belden Tofino Argon Fa-tsa-220-mm/mm Firmware | ||
Belden Tofino Argon Fa-tsa-220-mm/mm | ||
Belden Tofino Argon Fa-tsa-100-tx/tx Firmware | ||
Belden Tofino Argon Fa-tsa-100-tx/tx | ||
Belden Eagle 20 Tofino 943 987-505-mm/mm Firmware | ||
Belden Eagle 20 Tofino 943 987-505-mm/mm | ||
Belden Eagle 20 Tofino 943 987-504-mm/tx Firmware | ||
Belden Eagle 20 Tofino 943 987-504-mm/tx | ||
Belden Eagle 20 Tofino 943 987-502 -tx/mm Firmware | ||
Belden Eagle 20 Tofino 943 987-502 | ||
Belden Eagle 20 Tofino 943 987-501-tx/tx Firmware | ||
Belden Eagle 20 Tofino | ||
Schneider-electric Tcsefea23f3f20 Firmware | ||
Schneider-electric Tcsefea23f3f20 | ||
Schneider-electric Tcsefea23f3f21 Firmware | ||
Schneider-electric Tcsefea23f3f21 | ||
Schneider-electric Tcsefea23f3f22 Firmware | <03.23 | |
Schneider-electric Tcsefea23f3f22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-30065.
CVE-2021-30065 has a severity of 7.5 (high).
Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance firmware up to version 03.2.03 are affected by CVE-2021-30065.
Crafted ModBus packets can bypass the ModBus enforcer in CVE-2021-30065 due to an incomplete fix of CVE-2017-11401.
You can find more information about CVE-2021-30065 at the following references: [link1](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-05), [link2](https://www.belden.com/support/security-assurance).