CVE-2013-6884
high · 10The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.
10
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2014-01-07
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-255
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cru-inc | ditto_forensic_fieldstation_firmware | <= 2013jun30a |
| cru-inc | ditto_forensic_fieldstation | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/124420/Ditto-Forensic-FieldStation-2013Oct15a-XSS-CSRF-Command-Execution.html
- http://seclists.org/fulldisclosure/2013/Dec/80
- http://secunia.com/advisories/55989
- http://www.cru-inc.com/support/software-downloads/ditto-firmware-updates/ditto-firmware-release-notes-2013jun30a/
- http://www.cru-inc.com/support/software-downloads/ditto-firmware-updates/ditto-firmware-release-notes-2013oct15a/
- http://www.exploit-db.com/exploits/30396
- http://packetstormsecurity.com/files/124420/Ditto-Forensic-FieldStation-2013Oct15a-XSS-CSRF-Command-Execution.html
- http://seclists.org/fulldisclosure/2013/Dec/80
- http://secunia.com/advisories/55989
- http://www.cru-inc.com/support/software-downloads/ditto-firmware-updates/ditto-firmware-release-notes-2013jun30a/
- http://www.cru-inc.com/support/software-downloads/ditto-firmware-updates/ditto-firmware-release-notes-2013oct15a/
- http://www.exploit-db.com/exploits/30396
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-6884