Description
The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42196 | The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password. |
References
History
Wed, 30 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-30T18:10:54.587Z
Reserved: 2023-07-16T00:00:00.000Z
Link: CVE-2023-38379
Updated: 2024-08-02T17:39:12.817Z
Status : Modified
Published: 2023-07-16T17:15:09.337
Modified: 2024-11-21T08:13:26.590
Link: CVE-2023-38379
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD