CVE-2023-29410

A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated
attacker to gain the same privilege as the application on the server when a malicious payload is
provided over HTTP for the server to execute. 

 



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
schneiderCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
schneider-electricinsighthome_firmware
𝑥
< 1.16
schneider-electricinsighthome_firmware
1.16
schneider-electricinsighthome_firmware
1.16:build_004
schneider-electricinsightfacility_firmware
𝑥
< 1.16
schneider-electricinsightfacility_firmware
1.16
schneider-electricinsightfacility_firmware
1.16:build_004
schneider-electricconext_gateway_firmware
𝑥
< 1.16
schneider-electricconext_gateway_firmware
1.16
schneider-electricconext_gateway_firmware
1.16:build_004
𝑥
= Vulnerable software versions