CVE-2023-30801 Vulnerability Details

  /     /     /  

CVE-2023-30801 Metadata Quick Info

CVE Published: 10/10/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: VulnCheck | Vendor: qBittorrent | Product: qBittorrent client
Status : PUBLISHED

CVE-2023-30801 Description

All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.

Metrics

CVSS Version: 3.1 | Base Score: 9.8 CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-1392
CWE Name: CWE-1392: Use of Default Credentials
Source: qBittorrent

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-70
CAPEC Description: CAPEC-70 Try Common or Default Usernames and Passwords


Source: NVD (National Vulnerability Database).