CVE-2021-30065: High severity belden tofino xenon security appliance firmware vulnerability
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-30065.
What is the severity of CVE-2021-30065?
CVE-2021-30065 has a severity of 7.5 (high).
Which software versions are affected by CVE-2021-30065?
Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance firmware up to version 03.2.03 are affected by CVE-2021-30065.
How can crafted ModBus packets bypass the ModBus enforcer in CVE-2021-30065?
Crafted ModBus packets can bypass the ModBus enforcer in CVE-2021-30065 due to an incomplete fix of CVE-2017-11401.
Where can I find more information about CVE-2021-30065?
You can find more information about CVE-2021-30065 at the following references: [link1](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-05), [link2](https://www.belden.com/support/security-assurance).