First published: Thu Dec 14 2023(Updated: )
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider Electric NetBotz 450 Firmware | ||
Schneider Electric EB450 | ||
All of | ||
Schneider-electric Eb45e | ||
Schneider Electric EB45E | ||
All of | ||
Schneider Electric EH450 Firmware | ||
Schneider Electric EH450 | ||
All of | ||
Schneider Electric EH45E | ||
Schneider Electric EH45E | ||
All of | ||
Schneider Electric ER450 Firmware | ||
Schneider Electric ER450 | ||
All of | ||
Schneider Electric ER45E | ||
Schneider Electric ER45E | ||
All of | ||
Schneider-electric Jr240 Firmware | ||
Schneider-electric Jr240 Firmware | ||
All of | ||
Schneider Electric TBURJR900 Firmware | ||
Schneider-electric Jr900 Firmware | ||
All of | ||
Schneider-electric Qr450 Firmware | <2.7.0 | |
Schneider-electric Qr450 Firmware | ||
All of | ||
Schneider Electric Qr150 Firmware | <2.7.0 | |
Schneider Electric Qr150 Firmware | ||
All of | ||
Schneider Electric Qb450 Firmware | <2.7.0 | |
Schneider Electric Qb450 Firmware | ||
All of | ||
Schneider Electric Qb150 | <2.7.0 | |
Schneider Electric Qb150 | ||
All of | ||
Schneider Electric QP450 Firmware | <2.7.0 | |
Schneider Electric QP450 | ||
All of | ||
Schneider Electric QP150 Firmware | <2.7.0 | |
Schneider Electric QP150 | ||
All of | ||
Schneider Electric QH450 Firmware | <2.7.0 | |
Schneider Electric QH450 | ||
All of | ||
Schneider-electric Qh150 | <2.7.0 | |
Schneider Electric QH150 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5629 is classified as a CWE-601 vulnerability, indicating a medium severity level due to potential information disclosure through phishing.
To mitigate CVE-2023-5629, ensure proper validation and sanitization of all user-supplied input to prevent open redirects.
The impact of CVE-2023-5629 includes the risk of user redirection to untrusted sites, which can lead to phishing attacks.
CVE-2023-5629 affects multiple Schneider Electric firmware versions, including those for models like Eb450, Eb45e, Eh450, and several others listed.
As of now, Schneider Electric has issued a security notice regarding CVE-2023-5629, but details about firmware patches need to be confirmed directly from their communications.