CVE-2023-5399: Schneider Electric Spacelogic C-Bus Toolkit
Critical severity, CVSS 9.8. EPSS: 35.5% chance of exploitation in the next 30 days.
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.
Affected products
- Schneider Electric Spacelogic C-Bus Toolkit: before 1.16.4 (fixed in 1.16.4)
Published 2023-10-04. Last modified 2026-06-17.