CVE-2023-40710
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
In short
A device can be forced into an endless restart loop by flooding it with many HTTP requests if its web server is enabled but not properly configured. This causes the device to stop working until someone manually fixes it.
Technical detail
CWE-770 vulnerability in SNAP PAC S1 Firmware R10.3b allows denial of service through resource exhaustion. An adversary sending a large quantity of HTTP GET requests to an incompletely configured built-in web server triggers continuous device restarts, requiring manual intervention for recovery.
Summary generated and translated by AI from the official description.
An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests if the controller has the built-in web server enabled but does not have the built-in web server completely set up and configured for the SNAP PAC S1 Firmware version R10.3b
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected products
OPTO 22 · SNAP PAC S1