Unknown
CVE-2021-30066
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-30066
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- belden,
- schneider-electric
Products
- eagle 20 tofino 943 987-501-tx/tx firmware -,
- eagle 20 tofino 943 987-502 -tx/mm firmware -,
- eagle 20 tofino 943 987-504-mm/tx firmware -,
- eagle 20 tofino 943 987-505-mm/mm firmware -,
- tcsefea23f3f20 firmware -,
- tcsefea23f3f21 firmware -,
- tcsefea23f3f22 firmware,
- tofino argon fa-tsa-100-tx/tx firmware -,
- tofino argon fa-tsa-220-mm/mm firmware -,
- tofino argon fa-tsa-220-mm/tx firmware -,
- tofino argon fa-tsa-220-tx/mm firmware -,
- tofino argon fa-tsa-220-tx/tx firmware -,
- tofino xenon security appliance firmware
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: