CVE-2023-0321
Published: Jan 25, 2023
Modified: Mar 27, 2025
CVSS v3.1
9.1
Description
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files.
| Vendor | Product | Versions |
|---|---|---|
Campbell Scientific | CR6 | affected all version |
Campbell Scientific | CR300 | affected all version |
Campbell Scientific | CR800 | affected all version |
Campbell Scientific | CR1000 | affected all version |
Campbell Scientific | CR3000 | affected all version |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now