Vulnerability Description
Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siglent | Sds1204X-E Firmware | 6.1.37r9.ads |
| Siglent | Sds1204X-E | - |
| Siglent | Sds1104X-E Firmware | 6.1.37r9.ads |
| Siglent | Sds1104X-E | - |
| Siglent | Sds1074X-E Firmware | 6.1.37r9.ads |
| Siglent | Sds1074X-E | - |
References
- https://github.com/BretMcDanel/CVE/blob/main/CVE-2023-25367.mdExploitMitigationThird Party Advisory
- https://siglent.comProduct
- https://github.com/BretMcDanel/CVE/blob/main/CVE-2023-25367.mdExploitMitigationThird Party Advisory
- https://siglent.comProduct
FAQ
What is CVE-2023-25367?
CVE-2023-25367 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.
How severe is CVE-2023-25367?
CVE-2023-25367 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-25367?
Check the references section above for vendor advisories and patch information. Affected products include: Siglent Sds1204X-E Firmware, Siglent Sds1204X-E, Siglent Sds1104X-E Firmware, Siglent Sds1104X-E, Siglent Sds1074X-E Firmware.