First published: Thu Dec 14 2023(Updated: )
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Schneider-electric Eb450 | ||
Schneider-electric Eb450 Firmware | ||
All of | ||
Schneider-electric Eb45e | ||
Schneider-electric Eb45e | ||
All of | ||
Schneider-electric Eh450 | ||
Schneider-electric Eh450 Firmware | ||
All of | ||
Schneider-electric Eh45e | ||
Schneider-electric Eh45e Firmware | ||
All of | ||
Schneider-electric Er450 | ||
Schneider-electric Er450 Firmware | ||
All of | ||
Schneider Electric ER45E | ||
Schneider Electric ER45E | ||
All of | ||
Schneider-electric Jr240 Firmware | ||
Schneider-electric Jr240 Firmware | ||
All of | ||
Schneider-electric Jr900 Firmware | ||
Schneider-electric Jr900 Firmware | ||
All of | ||
Schneider-electric Qr450 Firmware | <2.7.0 | |
Schneider-electric Qr450 | ||
All of | ||
Schneider-electric Qr150 Firmware | <2.7.0 | |
Schneider-electric Qr150 | ||
All of | ||
Schneider-electric Qb450 Firmware | <2.7.0 | |
Schneider-electric Qb450 | ||
All of | ||
Schneider-electric Qb150 Firmware | <2.7.0 | |
Schneider-electric Qb150 | ||
All of | ||
Schneider-electric Qp450 Firmware | <2.7.0 | |
Schneider-electric Qp450 | ||
All of | ||
Schneider-electric Qp150 Firmware | <2.7.0 | |
Schneider-electric Qp150 | ||
All of | ||
Schneider-electric Qh450 Firmware | <2.7.0 | |
Schneider-electric Qh450 | ||
All of | ||
Schneider-electric Qh150 Firmware | <2.7.0 | |
Schneider-electric Qh150 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5630 is currently classified as high due to the potential for a privileged user to install untrusted firmware.
An attacker exploiting CVE-2023-5630 could install untrusted firmware, compromising the device's integrity and security.
Fixing CVE-2023-5630 involves applying the latest firmware updates provided by Schneider Electric that mitigate this vulnerability.
CVE-2023-5630 affects various Schneider Electric firmware versions, including the Eb450, Eb45e, Eh450, and several others up to version 2.7.0.
Yes, CVE-2023-5630 is specifically a vulnerability in firmware that allows untrusted code to be downloaded without integrity checks.