CVE-2021-30066

MEDIUM

Belden Tofino Xenon Security Appliance Firmware < 03.2.03 - Signature Verification Bypass

Title source: rule
STIX 2.1

Description

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://www.belden.com/support/security-assurance

Scores

CVSS v3 6.8
EPSS 0.0000
EPSS Percentile 0.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (13)
belden/eagle_20_tofino_943_987-501-tx\/tx_firmware
belden/eagle_20_tofino_943_987-502_-tx\/mm_firmware
belden/eagle_20_tofino_943_987-504-mm\/tx_firmware
belden/eagle_20_tofino_943_987-505-mm\/mm_firmware
belden/tofino_argon_fa-tsa-100-tx\/tx_firmware
belden/tofino_argon_fa-tsa-220-mm\/mm_firmware
belden/tofino_argon_fa-tsa-220-mm\/tx_firmware
belden/tofino_argon_fa-tsa-220-tx\/mm_firmware
belden/tofino_argon_fa-tsa-220-tx\/tx_firmware
belden/tofino_xenon_security_appliance_firmware < 03.2.03
... and 3 more
Published Apr 03, 2022
Tracked Since Feb 18, 2026