Cyber Resilience

CVE-2023-5630

Schneider-Electric Eb450 Firmware

Published
14 December 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS Score 0.0028 20th percentile
Risk Priority 41 floored blend · peak EPSS

Summary

CVE-2023-5630 is a medium-severity Download of Code Without Integrity Check (CWE-494) vulnerability in Schneider-Electric Eb450 Firmware. Its CVSS base score is 6.5 (Medium).

Operationally, ranked at the 20th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmware.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-5629Same product: Schneider-Electric Eb450
CVE-2023-5984Same vendor: Schneider-Electric
CVE-2024-5681Same vendor: Schneider-Electric
CVE-2024-37038Same vendor: Schneider-Electric
CVE-2026-2405Same vendor: Schneider-Electric
CVE-2023-27981Same vendor: Schneider-Electric
CVE-2023-25556Same vendor: Schneider-Electric
CVE-2023-5391Same vendor: Schneider-Electric
CVE-2023-37197Same vendor: Schneider-Electric
CVE-2023-5402Same vendor: Schneider-Electric

Affected Assets

schneider-electric
eb450 firmware
all versions
schneider-electric
eb45e firmware
all versions
schneider-electric
eh450 firmware
all versions
schneider-electric
eh45e firmware
all versions
schneider-electric
er450 firmware
all versions
schneider-electric
er45e firmware
all versions
schneider-electric
jr240 firmware
all versions
schneider-electric
jr900 firmware
all versions
schneider-electric
qr450 firmware
≤ 2.7.0
schneider-electric
qr150 firmware
≤ 2.7.0
+6 more product configuration(s) — see NVD for full list

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 9 hardening rules · 5 OS baselines
Validate
Prove the fix (OWASP ASVS)

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-494

Policies can require integrity verification of software prior to installation, reducing risks from unverified downloads.

addresses: CWE-494

Blocks installation of components lacking a valid signature, mitigating download or installation of code without integrity checks.

addresses: CWE-494

Acquisition and maintenance portions of the strategy drive requirements for integrity verification of downloaded or supplied code.

addresses: CWE-494

Mandating integrity control and approved-only changes during development prevents incorporation of code or components lacking integrity validation.

addresses: CWE-494

Supply chain protection requires integrity verification of acquired components, directly reducing insertion or tampering of malicious code during delivery.

addresses: CWE-494

Reduces exposure to code obtained without integrity verification by requiring assurance processes that confirm authenticity and absence of tampering.

addresses: CWE-494

Tamper resistance and detection commonly include integrity verification of code and firmware obtained from external sources.

addresses: CWE-494

Component authenticity requires verifying origin/integrity of acquired firmware or software, directly preventing inclusion of code without integrity checks.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

ID.RA-09 full match
prevents

Directly requires assessing authenticity/integrity of software before acquisition and use, preventing unverified downloads.

PR.DS-02 mostly match
prevents

Requires cryptographic integrity protections (signatures/hashes) for data-in-transit, covering downloaded code.

PR.PS-05 mostly match
prevents

Prevents execution of unauthorized software, blocking the outcome of an unchecked download.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Mandating integrity checks, digital signatures, and origin tracing for ICT components directly reduces the chance that code or firmware lacking an integrity check will be accepted into the organisation’s environment.

none

Requiring suppliers to disclose vulnerabilities and mandating verified updates lowers the chance that code lacking integrity checks will be deployed.

Hardening callouts derived

Configuration rules from DISA STIG baselines that reduce the attack surface for weaknesses of the type cited by this CVE. Derived transitively via CVE→CWE→STIG over `controls_xwalks` (authoritative rows only).

Oracle Linux 9 (1 rule)
  • V-271524 OL 9 must check the GPG signature of software packages originating from external software repositories before installation. via CWE-494

References