CVE-2023-29410
EUVD-2023-3297918.04.2023, 22:15
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| schneider-electric | insighthome_firmware | 𝑥 < 1.16 |
| schneider-electric | insighthome_firmware | 1.16 |
| schneider-electric | insighthome_firmware | 1.16:build_004 |
| schneider-electric | insightfacility_firmware | 𝑥 < 1.16 |
| schneider-electric | insightfacility_firmware | 1.16 |
| schneider-electric | insightfacility_firmware | 1.16:build_004 |
| schneider-electric | conext_gateway_firmware | 𝑥 < 1.16 |
| schneider-electric | conext_gateway_firmware | 1.16 |
| schneider-electric | conext_gateway_firmware | 1.16:build_004 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration