CVE-2021-30064

EUVD-2021-17008
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
beldentofino_xenon_security_appliance_firmware
𝑥
< 03.2.03
beldentofino_argon_fa-tsa-220-tx\/mm_firmware
-
beldentofino_argon_fa-tsa-220-tx\/tx_firmware
-
beldentofino_argon_fa-tsa-220-mm\/tx_firmware
-
beldentofino_argon_fa-tsa-220-mm\/mm_firmware
-
beldentofino_argon_fa-tsa-100-tx\/tx_firmware
-
beldeneagle_20_tofino_943_987-505-mm\/mm_firmware
-
beldeneagle_20_tofino_943_987-504-mm\/tx_firmware
-
beldeneagle_20_tofino_943_987-502_-tx\/mm_firmware
-
beldeneagle_20_tofino_943_987-501-tx\/tx_firmware
-
schneider-electrictcsefea23f3f20_firmware
-
schneider-electrictcsefea23f3f21_firmware
-
schneider-electrictcsefea23f3f22_firmware
𝑥
< 03.23
𝑥
= Vulnerable software versions