CVE Feed

    Dashboard / CVE / CVE-2023-0321

    CVE-2023-0321

    Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files.

    Published:Jan 25, 2023
    Last Modified:Mar 27, 2025
    EPS:Jan 25, 2023
    EPSS Score:0.00251
    CVSS Score:9.1

    Affected Products

    Vendor
    Campbellsci
    Product
    Cr1000
    Vendor
    Campbellsci
    Product
    Cr1000 Firmware
    Vendor
    Campbellsci
    Product
    Cr300
    Vendor
    Campbellsci
    Product
    Cr3000
    Vendor
    Campbellsci
    Product
    Cr3000 Firmware
    Vendor
    Campbellsci
    Product
    Cr300 Firmware
    Vendor
    Campbellsci
    Product
    Cr6
    Vendor
    Campbellsci
    Product
    Cr6 Firmware
    Vendor
    Campbellsci
    Product
    Cr800
    Vendor
    Campbellsci
    Product
    Cr800 Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High