PT-2017-9630 · Schneider Electric · Connexium Firewalls

George Lashenko

·

Published

2017-02-13

·

Updated

2017-03-15

·

CVE-2016-8352

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Schneider Electric ConneXium firewalls version TCSEFEC23F3F20 Schneider Electric ConneXium firewalls version TCSEFEC23F3F21 Schneider Electric ConneXium firewalls version TCSEFEC23FCF20 Schneider Electric ConneXium firewalls version TCSEFEC23FCF21 Schneider Electric ConneXium firewalls version TCSEFEC2CF3F20
Description A stack-based buffer overflow issue can be triggered during the SNMP login authentication process, potentially allowing an attacker to remotely execute code.
Recommendations For version TCSEFEC23F3F20, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC23F3F21, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC23FCF20, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC23FCF21, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC2CF3F20, consider disabling SNMP login authentication until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8352

Affected Products

Connexium Firewalls