CVE-2023-0321
Summary
| CVE | CVE-2023-0321 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-26 21:18:00 UTC |
| Updated | 2023-02-06 16:42:00 UTC |
| Description | Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Campbellsci | Cr1000 | - | All | All | All |
| Operating System | Campbellsci | Cr1000 Firmware | All | All | All | All |
| Hardware | Campbellsci | Cr300 | - | All | All | All |
| Hardware | Campbellsci | Cr3000 | - | All | All | All |
| Operating System | Campbellsci | Cr3000 Firmware | All | All | All | All |
| Operating System | Campbellsci | Cr300 Firmware | All | All | All | All |
| Hardware | Campbellsci | Cr6 | - | All | All | All |
| Operating System | Campbellsci | Cr6 Firmware | All | All | All | All |
| Hardware | Campbellsci | Cr800 | - | All | All | All |
| Operating System | Campbellsci | Cr800 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2023-0321 Divulgación de información sensible en productos de Campbell Scientific | CONFIRM | www.hackplayers.com | |
| Disclosure of Sensitive Information on Campbell Scientific Products | INCIBE-CERT | CONFIRM | www.incibe-cert.es | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Carlos Antonini Cepeda
There are currently no legacy QID mappings associated with this CVE.