CVE-2021-30066: High severity belden tofino xenon security appliance firmware vulnerability
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2021-30066.
What is the severity of CVE-2021-30066?
CVE-2021-30066 has a severity score of 6.8 (high).
Which software versions are affected by CVE-2021-30066?
Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance firmware versions up to and excluding 03.2.03 are affected.
How can an arbitrary firmware image be loaded on the affected devices?
The firmware signature verification for a USB stick can be bypassed, allowing an arbitrary firmware image to be loaded on the affected devices.
How can I fix CVE-2021-30066?
To fix CVE-2021-30066, it is recommended to update the affected devices to the latest firmware version that includes a fix for this vulnerability.