CVE-2021-30065

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AC:L/AV:N/A:N/C:N/I:H/PR:N/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
beldentofino_xenon_security_appliance_firmware
𝑥
< 03.2.03
beldentofino_argon_fa-tsa-220-tx\/mm_firmware
-
beldentofino_argon_fa-tsa-220-tx\/tx_firmware
-
beldentofino_argon_fa-tsa-220-mm\/tx_firmware
-
beldentofino_argon_fa-tsa-220-mm\/mm_firmware
-
beldentofino_argon_fa-tsa-100-tx\/tx_firmware
-
beldeneagle_20_tofino_943_987-505-mm\/mm_firmware
-
beldeneagle_20_tofino_943_987-504-mm\/tx_firmware
-
beldeneagle_20_tofino_943_987-502_-tx\/mm_firmware
-
beldeneagle_20_tofino_943_987-501-tx\/tx_firmware
-
schneider-electrictcsefea23f3f20_firmware
-
schneider-electrictcsefea23f3f21_firmware
-
schneider-electrictcsefea23f3f22_firmware
𝑥
< 03.23
𝑥
= Vulnerable software versions