CVE-2023-29410

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
18/04/2023
Last modified:
28/04/2023

Description

<br /> A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated<br /> attacker to gain the same privilege as the application on the server when a malicious payload is<br /> provided over HTTP for the server to execute. <br /> <br /> <br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:insighthome_firmware:*:*:*:*:*:*:*:* 1.16 (excluding)
cpe:2.3:o:schneider-electric:insighthome_firmware:1.16:-:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:insighthome_firmware:1.16:build_004:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:insighthome:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:insightfacility_firmware:*:*:*:*:*:*:*:* 1.16 (excluding)
cpe:2.3:o:schneider-electric:insightfacility_firmware:1.16:-:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:insightfacility_firmware:1.16:build_004:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:insightfacility:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:conext_gateway_firmware:*:*:*:*:*:*:*:* 1.16 (excluding)
cpe:2.3:o:schneider-electric:conext_gateway_firmware:1.16:-:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:conext_gateway_firmware:1.16:build_004:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:conext_gateway:-:*:*:*:*:*:*:*