A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow modified firmware to be uploaded when an authorized admin user begins a firmware update procedure which could result in full control over the device.
2023-11-15T04:15:19.043
2024-11-21T08:42:55.290
Modified
CVSSv3.1: 7.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | schneider-electric | ion8650_firmware | * | Yes |
| Hardware | schneider-electric | ion8650 | - | No |
| Operating System | schneider-electric | ion8800_firmware | * | Yes |
| Hardware | schneider-electric | ion8800 | - | No |