CVE-2021-30066
03.04.2022, 23:15
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.Enginsight
Vendor | Product | Version |
---|---|---|
belden | tofino_xenon_security_appliance_firmware | 𝑥 < 03.2.03 |
belden | tofino_argon_fa-tsa-220-tx\/mm_firmware | - |
belden | tofino_argon_fa-tsa-220-tx\/tx_firmware | - |
belden | tofino_argon_fa-tsa-220-mm\/tx_firmware | - |
belden | tofino_argon_fa-tsa-220-mm\/mm_firmware | - |
belden | tofino_argon_fa-tsa-100-tx\/tx_firmware | - |
belden | eagle_20_tofino_943_987-505-mm\/mm_firmware | - |
belden | eagle_20_tofino_943_987-504-mm\/tx_firmware | - |
belden | eagle_20_tofino_943_987-502_-tx\/mm_firmware | - |
belden | eagle_20_tofino_943_987-501-tx\/tx_firmware | - |
schneider-electric | tcsefea23f3f20_firmware | - |
schneider-electric | tcsefea23f3f21_firmware | - |
schneider-electric | tcsefea23f3f22_firmware | 𝑥 < 03.23 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration