Arbitrary Firmware Image Loading Vulnerability in Schneider Electric ConneXium Tofino Firewall and Belden Tofino Xenon Security Appliance

Arbitrary Firmware Image Loading Vulnerability in Schneider Electric ConneXium Tofino Firewall and Belden Tofino Xenon Security Appliance

CVE-2021-30066 · MEDIUM Severity

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

Learn more about our Web Application Penetration Testing UK.