CVE-2023-25367

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 14, 2023
Updated: Jan 3, 2025

Summary

CVE-2023-25367 is a remote code execution (RCE) vulnerability affecting Siglent SDS 1104X-E oscilloscopes running version V6.1.37R9.ADS of the software. The issue arises due to unfiltered user input in the SCPI interface and the web server, allowing malicious actors to execute arbitrary code remotely. Successful exploitation of this vulnerability could result in significant data loss or system compromise. Users are advised to update their software to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share