An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A hardcoded backdoor session ID exists that can be used for further access to the device, including reconfiguration tasks.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Apr 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Elspec-ltd
Elspec-ltd g5dfr
Elspec-ltd g5dfr Firmware
Weaknesses CWE-798
CPEs cpe:2.3:h:elspec-ltd:g5dfr:-:*:*:*:*:*:*:*
cpe:2.3:o:elspec-ltd:g5dfr_firmware:*:*:*:*:*:*:*:*
Vendors & Products Elspec-ltd
Elspec-ltd g5dfr
Elspec-ltd g5dfr Firmware

Mon, 18 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-18T18:45:25.456Z

Reserved: 2024-01-05T00:00:00

Link: CVE-2024-22083

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.834Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-20T05:15:45.800

Modified: 2025-04-16T17:29:30.663

Link: CVE-2024-22083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.