« Volver al listado

CVE-2016-8352

Estado: ModificadaCrítica (10)—

An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEFEC23F3F21 all versions, TCSEFEC23FCF20 all versions, TCSEFEC23FCF21 all versions, and TCSEFEC2CF3F20 all versions. A stack-based buffer overflow can be triggered during the SNMP login authentication process that may allow an attacker to remotely execute code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-8352",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Schneider Electric ConneXium TCSEFEC2*",
          "versions": [
            {
              "status": "affected",
              "version": "Schneider Electric ConneXium TCSEFEC2*"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-02-13T21:59:00.767",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/94062",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-16-306-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "http://www.securityfocus.com/bid/94062",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-16-306-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Schneider Electric ConneXium firewalls TCSEFEC23F3F20 all versions, TCSEFEC23F3F21 all versions, TCSEFEC23FCF20 all versions, TCSEFEC23FCF21 all versions, and TCSEFEC2CF3F20 all versions. A stack-based buffer overflow can be triggered during the SNMP login authentication process that may allow an attacker to remotely execute code."
    },
    {
      "lang": "es",
      "value": "Ha sido descubierto un problema en los cortafuegos Schneider Electric ConneXium TCSEFEC23F3F20 todas las versiones, TCSEFEC23F3F21 todas las versiones, TCSEFEC23FCF20 todas las versiones, TCSEFEC23FCF21 todas las versiones, y TCSEFEC2CF3F20 todas las versiones. Un desbordamiento de búfer basado en pila puede ser desencadenado durante el proceso de autenticación de inicio de sesión SNMP que puede permitir a un atacante ejecutar código remotamente."
    }
  ],
  "lastModified": "2026-06-17T00:54:12.253",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:schneider-electric:connexium_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0393FFB-DB2B-4C4E-95F2-CA1211467964"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:tcsefec23f3f20:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "98AE5D38-8266-4E4A-B52F-9CBEB022DD74"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:tcsefec23f3f21:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9E89FA24-0128-4DF4-BFFF-0FD2C8E0386F"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:tcsefec23fcf20:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7920453C-8B00-4E88-AB28-F051CEC2D0BA"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:tcsefec23fcf21:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AE3371CC-A330-4777-887A-2ED11FE1A039"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:tcsefec2cf3f20:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2BFDA3E0-E594-413D-98CB-5409FDBE60E4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}