First published: Wed Oct 04 2023(Updated: )
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
Credit: cybersecurity@se.com cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric C-bus Toolkit | <=1.16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5402 is critical with a severity value of 9.8.
CVE-2023-5402 is an Improper Privilege Management vulnerability that can lead to remote code execution when the transfer command is used over the network.
The Schneider-electric C-bus Toolkit version 1.16.3 is affected by CVE-2023-5402.
To fix CVE-2023-5402, it is recommended to update the Schneider-electric C-bus Toolkit to a version that is not affected by the vulnerability.
More information about CVE-2023-5402 can be found in the security and safety notice provided by Schneider-electric: [link](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-283-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-283-01.pdf)