Security Advisory

CVE-2017-11400

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-11-20 15:00:00
Last updated 2024-08-05 18:05:30
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker-controlled, data. This occurs because the appliance_config file is signed but the .tar.sec file is unsigned.