PT-2017-9630 · Schneider Electric · Connexium Firewalls
George Lashenko
·
Published
2017-02-13
·
Updated
2017-03-15
·
CVE-2016-8352
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Schneider Electric ConneXium firewalls version TCSEFEC23F3F20
Schneider Electric ConneXium firewalls version TCSEFEC23F3F21
Schneider Electric ConneXium firewalls version TCSEFEC23FCF20
Schneider Electric ConneXium firewalls version TCSEFEC23FCF21
Schneider Electric ConneXium firewalls version TCSEFEC2CF3F20
Description
A stack-based buffer overflow issue can be triggered during the SNMP login authentication process, potentially allowing an attacker to remotely execute code.
Recommendations
For version TCSEFEC23F3F20, consider disabling SNMP login authentication until a patch is available.
For version TCSEFEC23F3F21, consider disabling SNMP login authentication until a patch is available.
For version TCSEFEC23FCF20, consider disabling SNMP login authentication until a patch is available.
For version TCSEFEC23FCF21, consider disabling SNMP login authentication until a patch is available.
For version TCSEFEC2CF3F20, consider disabling SNMP login authentication until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Connexium Firewalls