Vulnerabilities > CVE-2023-38379 - Unspecified vulnerability in Rigol Mso5000 Firmware 00.01.03.00.03

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
rigol

Summary

The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to change the admin password via a zero-length pass0 to the webcontrol changepwd.cgi application, i.e., the entered password only needs to match the first zero characters of the saved password.

Vulnerable Configurations

Part Description Count
OS
Rigol
1
Hardware
Rigol
1