PT-2022-7700 · Siglent · Siglent Sds 1104X-E
Bret Mcdanel
·
Published
2022-12-30
·
Updated
2025-01-03
·
CVE-2023-25367
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Siglent SDS 1104X-E version 6.1.37R9.ADS
Description
The issue is related to unfiltered user input, which results in Remote Code Execution (RCE) through the SCPI interface or web server. This is due to insufficient input validation, allowing an attacker to execute arbitrary code remotely. The lack of authentication in the SCPI interface of the Siglent SDS1104X-E digital oscilloscope software is a key factor in this issue.
Recommendations
For Siglent SDS 1104X-E version 6.1.37R9.ADS, consider disabling the SCPI interface or restricting access to the web server as a temporary workaround until a patch is available. Restricting input validation to prevent unfiltered user input can also help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siglent Sds 1104X-E