CVE-2023-29410
18.04.2023, 22:15
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | insighthome_firmware | 𝑥 < 1.16 |
schneider-electric | insighthome_firmware | 1.16 |
schneider-electric | insighthome_firmware | 1.16:build_004 |
schneider-electric | insightfacility_firmware | 𝑥 < 1.16 |
schneider-electric | insightfacility_firmware | 1.16 |
schneider-electric | insightfacility_firmware | 1.16:build_004 |
schneider-electric | conext_gateway_firmware | 𝑥 < 1.16 |
schneider-electric | conext_gateway_firmware | 1.16 |
schneider-electric | conext_gateway_firmware | 1.16:build_004 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration