Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4w7-mqq9-4jc7

Опубликовано: 16 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.

EPSS

Процентиль: 21%
0.00066
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.

EPSS

Процентиль: 21%
0.00066
Низкий

7.5 High

CVSS3

Дефекты

CWE-306