High severity7.2NVD Advisory· Published Nov 15, 2023· Updated Jun 17, 2026
CVE-2023-5984
CVE-2023-5984
Description
A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorized admin user begins a firmware update procedure which could result in full control over the device.
Affected products
5- cpe:2.3:o:schneider-electric:ion8650_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:ion8800_firmware:*:*:*:*:*:*:*:*
- Range: All versions
- Range: All versions
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor Advisory
News mentions
0No linked articles in our index yet.