Vulnerability Description
A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Merten Instabus Tastermodul 1Fach System M Firmware | 1.0 |
| Schneider-Electric | Merten Instabus Tastermodul 1Fach System M | - |
| Schneider-Electric | Merten Instabus Tastermodul 2Fach System M Firmware | 1.0 |
| Schneider-Electric | Merten Instabus Tastermodul 2Fach System M | - |
| Schneider-Electric | Merten Tasterschnittstelle 4Fach Plus Firmware | 1.0 |
| Schneider-Electric | Merten Tasterschnittstelle 4Fach Plus | - |
| Schneider-Electric | Merten Knx Argus 180\/2\,20M Up System Firmware | 1.0 |
| Schneider-Electric | Merten Knx Argus 180\/2\,20M Up System | - |
| Schneider-Electric | Merten Jalousie-\/Schaltaktor Reg-K\/8X\/16X\/10 M. Hb Firmware | 1.0 |
| Schneider-Electric | Merten Jalousie-\/Schaltaktor Reg-K\/8X\/16X\/10 M. Hb | - |
| Schneider-Electric | Merten Knx Uni-Dimmaktor Ll Reg-K\/2X230\/300 W Firmware | 1.0 |
| Schneider-Electric | Merten Knx Uni-Dimmaktor Ll Reg-K\/2X230\/300 W | - |
| Schneider-Electric | Merten Knx Schaltakt.2X6A Up M.2 Eing. Firmware | 0.1 |
| Schneider-Electric | Merten Knx Schaltakt.2X6A Up M.2 Eing. | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-045-03&p_enDocVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-045-03&p_enDocVendor Advisory
FAQ
What is CVE-2023-25556?
CVE-2023-25556 is a vulnerability with a CVSS score of 8.3 (HIGH). A CWE-287: Improper Authentication vulnerability exists that could allow a device to be compromised when a key of less than seven digits is entered and the attacker has access to the KNX installation...
How severe is CVE-2023-25556?
CVE-2023-25556 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25556?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Merten Instabus Tastermodul 1Fach System M Firmware, Schneider-Electric Merten Instabus Tastermodul 1Fach System M, Schneider-Electric Merten Instabus Tastermodul 2Fach System M Firmware, Schneider-Electric Merten Instabus Tastermodul 2Fach System M, Schneider-Electric Merten Tasterschnittstelle 4Fach Plus Firmware.