NA

CVE-2023-29410

Published: 18/04/2023 Updated: 28/04/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated malicious user to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric insighthome_firmware

schneider-electric insighthome_firmware 1.16

schneider-electric insightfacility_firmware

schneider-electric insightfacility_firmware 1.16

schneider-electric conext_gateway_firmware

schneider-electric conext_gateway_firmware 1.16