ZDI-CAN-21115: ZDI-23-1797: Schneider Electric C-Bus Toolkit TransferCommand Exposed Dangerous Method Remote Code Execution Vulnerability
Published Dec 15, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric C-Bus Toolkit. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-5402.
Affected Software
1 affected component
Schneider Electric C-Bus Toolkit
Event History
Dec 15, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21115?
The severity of ZDI-CAN-21115 is rated at 9.8, indicating a critical vulnerability.
2
How do I fix ZDI-CAN-21115?
To fix ZDI-CAN-21115, update the Schneider Electric C-Bus Toolkit to the latest patched version as advised by the vendor.
3
What type of vulnerability is ZDI-CAN-21115?
ZDI-CAN-21115 is a remote code execution vulnerability that allows attackers to execute arbitrary code.
4
Is authentication required to exploit ZDI-CAN-21115?
No, authentication is not required to exploit ZDI-CAN-21115.
5
Which software is affected by ZDI-CAN-21115?
The affected software for ZDI-CAN-21115 is Schneider Electric C-Bus Toolkit.