CVE-2023-29410: Schneider Electric Conext Gateway Firmware
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
Affected products
- Schneider Electric Conext Gateway Firmware: before 1.16 (fixed in 1.16); version 1.16 only
- Schneider Electric Insightfacility Firmware: before 1.16 (fixed in 1.16); version 1.16 only
- Schneider Electric Insighthome Firmware: before 1.16 (fixed in 1.16); version 1.16 only
Published 2023-04-18. Last modified 2026-06-17.