CVE-2023-40708
MEDIUMCVSS 5.3/10EPSS 0.38%
Last modified
CVE-2023-40708 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opto22 | Snap Pac S1 Firmware | r10.3b |
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-02Third Party Advisory, US Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-02Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40708?
The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.
How severe is CVE-2023-40708?
CVE-2023-40708 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.38% probability of exploitation in the next 30 days.
How do I fix CVE-2023-40708?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-40702PingOne MFA Integration Kit contains a vulnerability where t…7.7
- CVE-2023-40703Mattermost fails to properly limit the characters allowed in…7.5
- CVE-2023-40704The product does not require unique and complex passwords to…9.8
- CVE-2023-40705Stored cross-site scripting vulnerability in Map setting pag…5.4
- CVE-2023-40706There is no limit on the number of login attempts in the web…9.8
- CVE-2023-40707There are no requirements for setting a complex password in …7.5
- CVE-2023-40709An adversary could crash the entire device by sending a larg…7.5
- CVE-2023-4071Heap buffer overflow in Visuals in Google Chrome prior to 11…8.8
- CVE-2023-40710An adversary could cause a continuous restart loop to the en…7.5
- CVE-2023-40711Veilid before 0.1.9 does not check the size of uncompressed …7.5
- CVE-2023-40712Apache Airflow, versions before 2.7.1, is affected by a vuln…6.5
- CVE-2023-40714A relative path traversal in Fortinet FortiSIEM versions 7.0…8.8
Are you affected by CVE-2023-40708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
