Description
The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error.
Published: 2026-03-31
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Anritsu has no plans to fix this issue. Anritsu recommends that users deploy Remote Spectrum Monitor within secure network environments to mitigate potential risks. Users can contact Anritsu Technical Support (1-800-267-4878) for more information.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Anritsu
Anritsu remote Spectrum Monitor Ms27100a
Anritsu remote Spectrum Monitor Ms27101a
Anritsu remote Spectrum Monitor Ms27102a
Anritsu remote Spectrum Monitor Ms27103a
Vendors & Products Anritsu
Anritsu remote Spectrum Monitor Ms27100a
Anritsu remote Spectrum Monitor Ms27101a
Anritsu remote Spectrum Monitor Ms27102a
Anritsu remote Spectrum Monitor Ms27103a

Tue, 31 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Description The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error.
Title Missing Authentication for Critical Function vulnerability in Anritsu Remote Spectrum Monitor
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Anritsu Remote Spectrum Monitor Ms27100a Remote Spectrum Monitor Ms27101a Remote Spectrum Monitor Ms27102a Remote Spectrum Monitor Ms27103a
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-03-31T18:40:17.359Z

Reserved: 2026-02-27T18:08:31.007Z

Link: CVE-2026-3356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-31T19:16:28.943

Modified: 2026-03-31T19:16:28.943

Link: CVE-2026-3356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-31T20:37:26Z

Weaknesses