« Volver al listado

CVE-2008-5848

Estado: ModificadaAlta (10)—

The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (14)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-5848",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-01-06T17:30:00.267",
  "references": [
    {
      "url": "http://ruxcon.org.au/files/2008/SIFT-Ruxcon2008-SCADA-Hacking-Modbus-Enabled-Devices.pdf",
      "tags": [
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.advantech.com.tw/support/DownloadSRDetail.aspx?SR_ID=1-95WMW",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ruxcon.org.au/presentations.shtml#13",
      "tags": [
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ruxcon.org.au/files/2008/SIFT-Ruxcon2008-SCADA-Hacking-Modbus-Enabled-Devices.pdf",
      "tags": [
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.advantech.com.tw/support/DownloadSRDetail.aspx?SR_ID=1-95WMW",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ruxcon.org.au/presentations.shtml#13",
      "tags": [
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        },
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity."
    },
    {
      "lang": "es",
      "value": "El módulo Advantech ADAM-6000 tiene 00000000 como su contraseña por defecto, lo que hace más fácil a atacantes remotos obtener acceso a través de una sesión HTTP, y (1) monitorizar o (2) controlar la actividad I/O del módulo Modbus/TCP."
    }
  ],
  "lastModified": "2026-06-16T23:01:05.847",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:advantech:adam-6015:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA03C4FC-451D-4D80-91A9-94B62F11CF3E"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6017:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23F14125-2C82-46B6-AA42-D17DAA9389F9"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6018:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCA43127-85F4-46F4-A67F-54B66BFB0D51"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35514F6C-F34A-420B-B08B-58388E4E772F"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6024:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A84898FB-2906-4798-BF9D-EE4DADD6B7D7"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6050:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51F66CE0-053B-4502-BE47-046F38D2E1EF"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6050w:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "066BDEE7-CD3B-482F-82A6-063F48EAEC02"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6051:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44CC898E-8BA4-401E-B95E-B22B4BD28658"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6051w:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E89BA4B7-C9A2-46F4-8B12-B72CF8767890"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6052:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F7CABA8-747E-454C-8100-39682281BD1A"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6060:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C011882-D383-46CA-8E20-D008D039AB81"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6060w:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C886F75-1B65-4695-9493-E3B1A647222A"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6066:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDE2AE5D-58E7-43D7-8E70-86ACDAD9A3E2"
            },
            {
              "criteria": "cpe:2.3:h:advantech:adam-6501:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "590DF4B1-9F0F-42A7-9579-602A27CB0B0F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}