CVE-2021-30066
MEDIUMBelden Tofino Xenon Security Appliance Firmware < 03.2.03 - Signature Verification Bypass
Title source: ruleDescription
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.belden.com/support/security-assurance
Vendor Advisory x_refsource_confirm
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-011-05
Scores
CVSS v3
6.8
EPSS
0.0000
EPSS Percentile
0.1%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-347
Status
published
Products (13)
belden/eagle_20_tofino_943_987-501-tx\/tx_firmware
belden/eagle_20_tofino_943_987-502_-tx\/mm_firmware
belden/eagle_20_tofino_943_987-504-mm\/tx_firmware
belden/eagle_20_tofino_943_987-505-mm\/mm_firmware
belden/tofino_argon_fa-tsa-100-tx\/tx_firmware
belden/tofino_argon_fa-tsa-220-mm\/mm_firmware
belden/tofino_argon_fa-tsa-220-mm\/tx_firmware
belden/tofino_argon_fa-tsa-220-tx\/mm_firmware
belden/tofino_argon_fa-tsa-220-tx\/tx_firmware
belden/tofino_xenon_security_appliance_firmware
< 03.2.03
... and 3 more
Published
Apr 03, 2022
Tracked Since
Feb 18, 2026