There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credentials.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-02 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Dragos

Published: 2023-08-24T16:05:48.352Z

Updated: 2023-08-24T16:05:48.352Z

Reserved: 2023-08-18T19:31:53.417Z


Link: CVE-2023-40707

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-08-24T17:15:08.967

Modified: 2023-08-29T23:34:10.753


Link: CVE-2023-40707

JSON object: View

cve-icon Redhat Information

No data.

CWE