On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.
En Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 versiones anteriores a 03.23, TCSEFEA23F3F20/21, y Belden Tofino Xenon Security Appliance, puede cargarse una imagen de firmware arbitraria porque puede omitirse la verificación de la firma del firmware (para una memoria USB). NOTA: este problema se presenta debido a una corrección incompleta de CVE-2017-11400
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | PHYSICAL |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:L/AC:L/Au:N/C:C/I:C/A:C
| Access Vector | LOCAL |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-347
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| belden | tofino_xenon_security_appliance_firmware | * | <built-in method update of dict object at 0x7e6071eaf700> | Operating System |
| belden | tofino_argon_fa-tsa-220-tx\/mm_firmware | - | <built-in method update of dict object at 0x7e6071eac4c0> | Operating System |
| belden | tofino_argon_fa-tsa-220-tx\/tx_firmware | - | <built-in method update of dict object at 0x7e6071eac900> | Operating System |
| belden | tofino_argon_fa-tsa-220-mm\/tx_firmware | - | <built-in method update of dict object at 0x7e6134291f40> | Operating System |
| belden | tofino_argon_fa-tsa-220-mm\/mm_firmware | - | <built-in method update of dict object at 0x7e6071eafa80> | Operating System |
| belden | tofino_argon_fa-tsa-100-tx\/tx_firmware | - | <built-in method update of dict object at 0x7e6071eadec0> | Operating System |
| belden | eagle_20_tofino_943_987-505-mm\/mm_firmware | - | <built-in method update of dict object at 0x7e60a8a56d80> | Operating System |
| belden | eagle_20_tofino_943_987-504-mm\/tx_firmware | - | <built-in method update of dict object at 0x7e6071eaf2c0> | Operating System |
| belden | eagle_20_tofino_943_987-502_-tx\/mm_firmware | - | <built-in method update of dict object at 0x7e60a8a543c0> | Operating System |
| belden | eagle_20_tofino_943_987-501-tx\/tx_firmware | - | <built-in method update of dict object at 0x7e6071eae680> | Operating System |
| schneider-electric | tcsefea23f3f20_firmware | - | <built-in method update of dict object at 0x7e6071eac240> | Operating System |
| schneider-electric | tcsefea23f3f21_firmware | - | <built-in method update of dict object at 0x7e61114e1380> | Operating System |
| schneider-electric | tcsefea23f3f22_firmware | * | <built-in method update of dict object at 0x7e6110a56e40> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:tofino_xenon_security_appliance_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:tofino_xenon_security_appliance:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:tofino_argon_fa-tsa-220-tx\/mm_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:tofino_argon_fa-tsa-220-tx\/mm:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:tofino_argon_fa-tsa-220-tx\/tx_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:tofino_argon_fa-tsa-220-tx\/tx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:tofino_argon_fa-tsa-220-mm\/tx_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:tofino_argon_fa-tsa-220-mm\/tx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:tofino_argon_fa-tsa-220-mm\/mm_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:tofino_argon_fa-tsa-220-mm\/mm:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:tofino_argon_fa-tsa-100-tx\/tx_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:tofino_argon_fa-tsa-100-tx\/tx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:eagle_20_tofino_943_987-505-mm\/mm_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:eagle_20_tofino_943_987-505-mm\/mm:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:eagle_20_tofino_943_987-504-mm\/tx_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:eagle_20_tofino_943_987-504-mm\/tx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:eagle_20_tofino_943_987-502_-tx\/mm_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:eagle_20_tofino_943_987-502_-tx\/mm:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:belden:eagle_20_tofino_943_987-501-tx\/tx_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:belden:eagle_20_tofino_943_987-501-tx\/tx:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tcsefea23f3f20_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tcsefea23f3f20:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tcsefea23f3f21_firmware:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tcsefea23f3f21:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:schneider-electric:tcsefea23f3f22_firmware:*:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:tcsefea23f3f22:-:*:*:*:*:*:*:* |