HIGH · 7.5

CVE-2021-30065

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE:...

Vulnerability Description

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
BeldenTofino Xenon Security Appliance Firmware< 03.2.03
BeldenTofino Xenon Security Appliance-
BeldenTofino Argon Fa-Tsa-220-Tx\/Mm Firmware-
BeldenTofino Argon Fa-Tsa-220-Tx\/Mm-
BeldenTofino Argon Fa-Tsa-220-Tx\/Tx Firmware-
BeldenTofino Argon Fa-Tsa-220-Tx\/Tx-
BeldenTofino Argon Fa-Tsa-220-Mm\/Tx Firmware-
BeldenTofino Argon Fa-Tsa-220-Mm\/Tx-
BeldenTofino Argon Fa-Tsa-220-Mm\/Mm Firmware-
BeldenTofino Argon Fa-Tsa-220-Mm\/Mm-
BeldenTofino Argon Fa-Tsa-100-Tx\/Tx Firmware-
BeldenTofino Argon Fa-Tsa-100-Tx\/Tx-
BeldenEagle 20 Tofino 943 987-505-Mm\/Mm Firmware-
BeldenEagle 20 Tofino 943 987-505-Mm\/Mm-
BeldenEagle 20 Tofino 943 987-504-Mm\/Tx Firmware-
BeldenEagle 20 Tofino 943 987-504-Mm\/Tx-
BeldenEagle 20 Tofino 943 987-502 -Tx\/Mm Firmware-
BeldenEagle 20 Tofino 943 987-502 -Tx\/Mm-
BeldenEagle 20 Tofino 943 987-501-Tx\/Tx Firmware-
BeldenEagle 20 Tofino 943 987-501-Tx\/Tx-

References

FAQ

What is CVE-2021-30065?

CVE-2021-30065 is a vulnerability with a CVSS score of 7.5 (HIGH). On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE:...

How severe is CVE-2021-30065?

CVE-2021-30065 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-30065?

Check the references section above for vendor advisories and patch information. Affected products include: Belden Tofino Xenon Security Appliance Firmware, Belden Tofino Xenon Security Appliance, Belden Tofino Argon Fa-Tsa-220-Tx\/Mm Firmware, Belden Tofino Argon Fa-Tsa-220-Tx\/Mm, Belden Tofino Argon Fa-Tsa-220-Tx\/Tx Firmware.