Lucene search

K
nvd[email protected]NVD:CVE-2021-30064
HistoryApr 03, 2022 - 10:15 p.m.

CVE-2021-30064

2022-04-0322:15:14
CWE-798
web.nvd.nist.gov
4
schneider electric
connexium tofino
firewall
ssh
hardcoded credentials
security appliance

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.5%

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

Affected configurations

Nvd
Node
beldentofino_xenon_security_appliance_firmwareRange<03.2.03
AND
beldentofino_xenon_security_applianceMatch-
Node
beldentofino_argon_fa-tsa-220-tx\/mm_firmwareMatch-
AND
beldentofino_argon_fa-tsa-220-tx\/mmMatch-
Node
beldentofino_argon_fa-tsa-220-tx\/tx_firmwareMatch-
AND
beldentofino_argon_fa-tsa-220-tx\/txMatch-
Node
beldentofino_argon_fa-tsa-220-mm\/tx_firmwareMatch-
AND
beldentofino_argon_fa-tsa-220-mm\/txMatch-
Node
beldentofino_argon_fa-tsa-220-mm\/mm_firmwareMatch-
AND
beldentofino_argon_fa-tsa-220-mm\/mmMatch-
Node
beldentofino_argon_fa-tsa-100-tx\/tx_firmwareMatch-
AND
beldentofino_argon_fa-tsa-100-tx\/txMatch-
Node
beldeneagle_20_tofino_943_987-505-mm\/mm_firmwareMatch-
AND
beldeneagle_20_tofino_943_987-505-mm\/mmMatch-
Node
beldeneagle_20_tofino_943_987-504-mm\/tx_firmwareMatch-
AND
beldeneagle_20_tofino_943_987-504-mm\/txMatch-
Node
beldeneagle_20_tofino_943_987-502_-tx\/mm_firmwareMatch-
AND
beldeneagle_20_tofino_943_987-502_-tx\/mmMatch-
Node
beldeneagle_20_tofino_943_987-501-tx\/tx_firmwareMatch-
AND
beldeneagle_20_tofino_943_987-501-tx\/txMatch-
Node
schneider-electrictcsefea23f3f20_firmwareMatch-
AND
schneider-electrictcsefea23f3f20Match-
Node
schneider-electrictcsefea23f3f21_firmwareMatch-
AND
schneider-electrictcsefea23f3f21Match-
Node
schneider-electrictcsefea23f3f22_firmwareRange<03.23
AND
schneider-electrictcsefea23f3f22Match-
VendorProductVersionCPE
beldentofino_xenon_security_appliance_firmware*cpe:2.3:o:belden:tofino_xenon_security_appliance_firmware:*:*:*:*:*:*:*:*
beldentofino_xenon_security_appliance-cpe:2.3:h:belden:tofino_xenon_security_appliance:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-tx\/mm_firmware-cpe:2.3:o:belden:tofino_argon_fa-tsa-220-tx\/mm_firmware:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-tx\/mm-cpe:2.3:h:belden:tofino_argon_fa-tsa-220-tx\/mm:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-tx\/tx_firmware-cpe:2.3:o:belden:tofino_argon_fa-tsa-220-tx\/tx_firmware:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-tx\/tx-cpe:2.3:h:belden:tofino_argon_fa-tsa-220-tx\/tx:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-mm\/tx_firmware-cpe:2.3:o:belden:tofino_argon_fa-tsa-220-mm\/tx_firmware:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-mm\/tx-cpe:2.3:h:belden:tofino_argon_fa-tsa-220-mm\/tx:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-mm\/mm_firmware-cpe:2.3:o:belden:tofino_argon_fa-tsa-220-mm\/mm_firmware:-:*:*:*:*:*:*:*
beldentofino_argon_fa-tsa-220-mm\/mm-cpe:2.3:h:belden:tofino_argon_fa-tsa-220-mm\/mm:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

60.5%

Related for NVD:CVE-2021-30064