← Back to browse · API

CVE-2023-5399

Severity
CRITICAL
CVSS
9.8
EPSS
0.38524
Risk score
52.68
CISA KEV
No
PoC
No
Published
2023-10-04
Modified
2025-02-27
First seen
2026-08-07
Aliases
EUVD-2023-57714, GHSA-XVCP-F5RW-F54W
Products
Schneider Electric:C-Bus Toolkit v1.16.3 and prior
Sources
euvd EUVD-2023-57714

Description

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.

References