ZDI-23-1796: Schneider Electric C-Bus Toolkit FileCommand Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric C-Bus Toolkit. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-5399.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1796?
The ZDI-23-1796 vulnerability has a CVSS rating of 9.8, indicating it is critical.
How do I fix ZDI-23-1796?
To mitigate ZDI-23-1796, it is recommended to update the Schneider Electric C-Bus Toolkit to the latest version provided by the vendor.
Who is impacted by ZDI-23-1796?
Organizations using affected installations of Schneider Electric C-Bus Toolkit without authentication are at risk from ZDI-23-1796.
What type of attack does ZDI-23-1796 allow?
ZDI-23-1796 allows remote attackers to execute arbitrary code on vulnerable systems.
Is authentication required to exploit ZDI-23-1796?
No, authentication is not required to exploit the ZDI-23-1796 vulnerability.