CVE-2023-5399: Schneider Electric Spacelogic C-Bus Toolkit

Critical severity, CVSS 9.8. EPSS: 35.5% chance of exploitation in the next 30 days.

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.

Affected products

Published 2023-10-04. Last modified 2026-06-17.