CVE Vulnerabilities

CVE-2023-38379

Published: Jul 16, 2023 | Modified: Jul 26, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.

Affected Software

Name Vendor Start Version End Version
Mso5000_firmware Rigol 00.01.03.00.03 (including) 00.01.03.00.03 (including)

References