CVE-2021-30064

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
beldentofino_xenon_security_appliance_firmware
𝑥
< 03.2.03
beldentofino_argon_fa-tsa-220-tx\/mm_firmware
-
beldentofino_argon_fa-tsa-220-tx\/tx_firmware
-
beldentofino_argon_fa-tsa-220-mm\/tx_firmware
-
beldentofino_argon_fa-tsa-220-mm\/mm_firmware
-
beldentofino_argon_fa-tsa-100-tx\/tx_firmware
-
beldeneagle_20_tofino_943_987-505-mm\/mm_firmware
-
beldeneagle_20_tofino_943_987-504-mm\/tx_firmware
-
beldeneagle_20_tofino_943_987-502_-tx\/mm_firmware
-
beldeneagle_20_tofino_943_987-501-tx\/tx_firmware
-
schneider-electrictcsefea23f3f20_firmware
-
schneider-electrictcsefea23f3f21_firmware
-
schneider-electrictcsefea23f3f22_firmware
𝑥
< 03.23
𝑥
= Vulnerable software versions