CVE-2021-30064

CRITICAL

Schneider Electric ConneXium - Auth Bypass

Title source: llm
STIX 2.1

Description

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.belden.com/support/security-assurance

Scores

CVSS v3 9.8
EPSS 0.0006
EPSS Percentile 18.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (13)
belden/eagle_20_tofino_943_987-501-tx\/tx_firmware
belden/eagle_20_tofino_943_987-502_-tx\/mm_firmware
belden/eagle_20_tofino_943_987-504-mm\/tx_firmware
belden/eagle_20_tofino_943_987-505-mm\/mm_firmware
belden/tofino_argon_fa-tsa-100-tx\/tx_firmware
belden/tofino_argon_fa-tsa-220-mm\/mm_firmware
belden/tofino_argon_fa-tsa-220-mm\/tx_firmware
belden/tofino_argon_fa-tsa-220-tx\/mm_firmware
belden/tofino_argon_fa-tsa-220-tx\/tx_firmware
belden/tofino_xenon_security_appliance_firmware < 03.2.03
... and 3 more
Published Apr 03, 2022
Tracked Since Feb 18, 2026