SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-40708

This could allow an adversary to access some device files.

MEDIUM 5.3EPSS 0.48%

Does this matter?

Lower severity and a low EPSS score (0.48%). Track it; it rarely justifies an emergency change on its own.

Description

The File Transfer Protocol (FTP) port is open by default in the SNAP PAC S1 Firmware version R10.3b. This could allow an adversary to access some device files.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.48% probability · 40th percentile
CISA KEV
Not listed
Weakness
CWE-1188
Affected
opto22/snap pac s1 firmware
Source
ot-cert@dragos.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.