CVE-2023-29410

EUVD-2023-32979
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated
attacker to gain the same privilege as the application on the server when a malicious payload is
provided over HTTP for the server to execute. 

 



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
schneiderCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
schneider-electricinsighthome_firmware
𝑥
< 1.16
schneider-electricinsighthome_firmware
1.16
schneider-electricinsighthome_firmware
1.16:build_004
schneider-electricinsightfacility_firmware
𝑥
< 1.16
schneider-electricinsightfacility_firmware
1.16
schneider-electricinsightfacility_firmware
1.16:build_004
schneider-electricconext_gateway_firmware
𝑥
< 1.16
schneider-electricconext_gateway_firmware
1.16
schneider-electricconext_gateway_firmware
1.16:build_004
𝑥
= Vulnerable software versions