CVE-2023-5402: Critical severity schneider electric spacelogic c-bus toolkit vulnerability
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5402?
The severity of CVE-2023-5402 is critical with a severity value of 9.8.
What is the vulnerability description of CVE-2023-5402?
CVE-2023-5402 is an Improper Privilege Management vulnerability that can lead to remote code execution when the transfer command is used over the network.
Which software is affected by CVE-2023-5402?
The Schneider-electric C-bus Toolkit version 1.16.3 is affected by CVE-2023-5402.
How can I fix CVE-2023-5402?
To fix CVE-2023-5402, it is recommended to update the Schneider-electric C-bus Toolkit to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2023-5402?
More information about CVE-2023-5402 can be found in the security and safety notice provided by Schneider-electric: [link](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-283-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-283-01.pdf)