Vulnerability Description
A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | C-Bus Toolkit | <= 1.16.3 |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-283-01&p_enDocVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-283-01&p_enDocVendor Advisory
FAQ
What is CVE-2023-5402?
CVE-2023-5402 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.
How severe is CVE-2023-5402?
CVE-2023-5402 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-5402?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric C-Bus Toolkit.