First published: Tue Apr 18 2023(Updated: )
A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Merten Instabus Tastermodul 1fach System M | =1.0 | |
Schneider-electric Merten Instabus Tastermodul 1fach System M Firmware | ||
Schneider-electric Merten Instabus Tastermodul 2fach System M | =1.0 | |
Schneider-electric Merten Instabus Tastermodul 2fach System M Firmware | ||
Schneider-electric Merten Tasterschnittstelle 4fach Plus Firmware | =1.0 | |
Schneider-electric Merten Tasterschnittstelle 4fach Plus Firmware | =1.2 | |
Schneider-electric Merten Tasterschnittstelle 4fach Plus | ||
Schneider-electric Merten Knx Argus 180/2,20m Up System Firmware | =1.0 | |
Schneider-electric Merten Knx Argus 180/2,20m Up System | ||
Schneider-electric Merten Jalousie-geschaltaktor Reg-k/8x/16x/10 M. Hb | =1.0 | |
Schneider-electric Merten Jalousie-geschaltaktor Reg-k/8x/16x/10 M. Hb | ||
Schneider-electric Merten Knx Uni-dimmaktor Ll Reg-k\/2x230\/300 W Firmware | =1.0 | |
Schneider-electric Merten Knx Uni-dimmaktor Ll Reg-k\/2x230\/300 W Firmware | =1.1 | |
Schneider-electric Merten Knx Uni-dimmaktor Ll Reg-k\/2x230\/300 W | ||
Schneider Electric Merten KNX Schaltaktor 2x6A UP M.2 Eing. | =0.1 | |
Schneider Electric Merten KNX Schaltaktor 2x6A UP M.2 Eing. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security notice is CVE-2023-25556.
The severity of CVE-2023-25556 is rated as high with a severity value of 8.8.
The CWE ID associated with CVE-2023-25556 is CWE-287: Improper Authentication.
The affected software versions are Schneider Electric Merten Instabus Tastermodul 1-fach System M Firmware 1.0, Schneider Electric Merten Instabus Tastermodul 2-fach System M Firmware 1.0, Schneider Electric Merten Tasterschnittstelle 4-fach Plus Firmware 1.0 and 1.2, and Schneider Electric Merten KNX Argus 180/2,20m UP System Firmware 1.0.
CVE-2023-25556 can be exploited when a key of less than seven digits is entered and the attacker has access to the KNX installation.