The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to execute arbitrary code via shell metacharacters in pass1 to the webcontrol changepwd.cgi application.
References
Link Resource
https://news.ycombinator.com/item?id=36745664 Issue Tracking Third Party Advisory
https://tortel.li/post/insecure-scope/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-07-16T00:00:00

Updated: 2023-07-16T00:00:00

Reserved: 2023-07-16T00:00:00


Link: CVE-2023-38378

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-16T17:15:09.277

Modified: 2023-07-26T01:11:51.500


Link: CVE-2023-38378

JSON object: View

cve-icon Redhat Information

No data.

CWE