CRITICAL · 9.8

CVE-2021-30064

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials ...

Vulnerability Description

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BeldenTofino Xenon Security Appliance Firmware< 03.2.03
BeldenTofino Xenon Security Appliance-
BeldenTofino Argon Fa-Tsa-220-Tx\/Mm Firmware-
BeldenTofino Argon Fa-Tsa-220-Tx\/Mm-
BeldenTofino Argon Fa-Tsa-220-Tx\/Tx Firmware-
BeldenTofino Argon Fa-Tsa-220-Tx\/Tx-
BeldenTofino Argon Fa-Tsa-220-Mm\/Tx Firmware-
BeldenTofino Argon Fa-Tsa-220-Mm\/Tx-
BeldenTofino Argon Fa-Tsa-220-Mm\/Mm Firmware-
BeldenTofino Argon Fa-Tsa-220-Mm\/Mm-
BeldenTofino Argon Fa-Tsa-100-Tx\/Tx Firmware-
BeldenTofino Argon Fa-Tsa-100-Tx\/Tx-
BeldenEagle 20 Tofino 943 987-505-Mm\/Mm Firmware-
BeldenEagle 20 Tofino 943 987-505-Mm\/Mm-
BeldenEagle 20 Tofino 943 987-504-Mm\/Tx Firmware-
BeldenEagle 20 Tofino 943 987-504-Mm\/Tx-
BeldenEagle 20 Tofino 943 987-502 -Tx\/Mm Firmware-
BeldenEagle 20 Tofino 943 987-502 -Tx\/Mm-
BeldenEagle 20 Tofino 943 987-501-Tx\/Tx Firmware-
BeldenEagle 20 Tofino 943 987-501-Tx\/Tx-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-30064?

CVE-2021-30064 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials ...

How severe is CVE-2021-30064?

CVE-2021-30064 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-30064?

Check the references section above for vendor advisories and patch information. Affected products include: Belden Tofino Xenon Security Appliance Firmware, Belden Tofino Xenon Security Appliance, Belden Tofino Argon Fa-Tsa-220-Tx\/Mm Firmware, Belden Tofino Argon Fa-Tsa-220-Tx\/Mm, Belden Tofino Argon Fa-Tsa-220-Tx\/Tx Firmware.