7.5
CVE-2023-38379
- EPSS 0.13%
- Veröffentlicht 16.07.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:13:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rigol ≫ Mso5000 Firmware Version00.01.03.00.03
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.322 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.