CVE-2023-0321
Disclosure of Sensitive Information on Campbell Scientific Products
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Productos afectados
Campbell Scientific · CR1000Campbell Scientific · CR300Campbell Scientific · CR3000Campbell Scientific · CR6Campbell Scientific · CR800¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →