CVE-2023-5629: High severity schneider electric netbotz 450 firmware vulnerability
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5629?
CVE-2023-5629 is classified as a CWE-601 vulnerability, indicating a medium severity level due to potential information disclosure through phishing.
How do I fix CVE-2023-5629?
To mitigate CVE-2023-5629, ensure proper validation and sanitization of all user-supplied input to prevent open redirects.
What is the impact of CVE-2023-5629?
The impact of CVE-2023-5629 includes the risk of user redirection to untrusted sites, which can lead to phishing attacks.
Which products are affected by CVE-2023-5629?
CVE-2023-5629 affects multiple Schneider Electric firmware versions, including those for models like Eb450, Eb45e, Eh450, and several others listed.
Is there a patch available for CVE-2023-5629?
As of now, Schneider Electric has issued a security notice regarding CVE-2023-5629, but details about firmware patches need to be confirmed directly from their communications.