IM
IronMonkey Threat Research

CVE-2017-11400 HIGH

Published: 2017-11-20 | Last Modified: 2026-06-17 | Status: Modified

Description

An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker-controlled, data. This occurs because the appliance_config file is signed but the .tar.sec file is unsigned.

Additional Descriptions (1)

Se ha descubierto un problema en las versiones anteriores a la 03.2.00 de Belden Hirschmann Tofino Xenon Security Appliance. Una firma incompleta del firmware permite que un atacante local actualice el equipamiento (kernel, sistema de archivo) con datos no firmados controlados por el atacante. Esto ocurre debido a que el archivo appliance_config está firmado, pero el archivo .tar.sec no lo está.

CVSS Metrics

Base Score: 7.2 (HIGH)

AV:L/AC:L/Au:N/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-347

Affected Products

Vendor Product Version Update Type
belden tofino_xenon_security_appliance_firmware * <built-in method update of dict object at 0x72a9cd0c3bc0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:belden:tofino_xenon_security_appliance_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:belden:tofino_xenon_security_appliance:-:*:*:*:*:*:*:*
Notification
Message here