ZDI-CAN-21129: ZDI-23-1796: Schneider Electric C-Bus Toolkit FileCommand Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric C-Bus Toolkit. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-5399.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21129?
ZDI-CAN-21129 has been assigned a CVSS rating of 9.8, indicating a critical severity level.
How do I fix ZDI-CAN-21129?
To mitigate ZDI-CAN-21129, it's recommended to update the Schneider Electric C-Bus Toolkit to the latest version provided by the vendor.
What types of attacks can exploit ZDI-CAN-21129?
ZDI-CAN-21129 allows remote attackers to execute arbitrary code on affected installations without requiring authentication.
Which software is affected by ZDI-CAN-21129?
ZDI-CAN-21129 affects Schneider Electric's C-Bus Toolkit installations.
Is authentication required to exploit ZDI-CAN-21129?
No, authentication is not required to exploit ZDI-CAN-21129, making it particularly dangerous.