CVE-2023-28004: Out-of-bounds Read
Published Apr 18, 2023
·Updated
A CWE-129: Improper validation of an array index vulnerability exists where a specially crafted Ethernet request could result in denial of service or remote code execution.
Affected Software
2 affected components
Schneider-electric Powerlogic Hdpm6000 Firmware<=0.58.6
Schneider-electric Powerlogic Hdpm6000
Remediation
Event History
Apr 18, 2023
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-28004.
2
What is the severity of CVE-2023-28004?
The severity of CVE-2023-28004 is critical (9.8).
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-129.
4
What is the affected software for CVE-2023-28004?
The affected software for CVE-2023-28004 is Schneider-electric Powerlogic Hdpm6000 Firmware version up to 0.58.6.
5
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specially crafted Ethernet request, which could result in denial of service or remote code execution.