First published: Wed Jun 14 2023(Updated: )
A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Foxboro Dcs Control Core Services |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2569 is high with a severity value of 7.8.
CVE-2023-2569 can cause local denial-of-service, elevation of privilege, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
Schneider-electric Ecostruxure Foxboro Dcs Control Core Services is affected by CVE-2023-2569.
Apply the security patch/fix provided by Schneider Electric as mentioned in the security notice: https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-164-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-164-04.pdf.
The CWE ID for CVE-2023-2569 is CWE-787.