CVE-2023-25367
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jun 14, 2023
Updated: Jan 3, 2025
Summary
CVE-2023-25367 is a remote code execution (RCE) vulnerability affecting Siglent SDS 1104X-E oscilloscopes running version V6.1.37R9.ADS of the software. The issue arises due to unfiltered user input in the SCPI interface and the web server, allowing malicious actors to execute arbitrary code remotely. Successful exploitation of this vulnerability could result in significant data loss or system compromise. Users are advised to update their software to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- SIGLENT