CVE-2013-6884
Cru-inc Ditto Forensic Fieldstation Firmware - Credentials Management
Title source: ruleDescription
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.
Exploits (1)
References (6)
Core 6
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/55989
Vendor Advisory x_refsource_misc
http://www.cru-inc.com/support/software-downloads/ditto-firmware-updates/ditto-firmware-release-notes-2013jun30a/
Exploit x_refsource_misc
http://packetstormsecurity.com/files/124420/Ditto-Forensic-FieldStation-2013Oct15a-XSS-CSRF-Command-Execution.html
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Dec/80
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/30396
Vendor Advisory x_refsource_misc
http://www.cru-inc.com/support/software-downloads/ditto-firmware-updates/ditto-firmware-release-notes-2013oct15a/
Scores
EPSS
0.3012
EPSS Percentile
96.7%
Details
CWE
CWE-255
Status
published
Products (2)
cru-inc/ditto_forensic_fieldstation
cru-inc/ditto_forensic_fieldstation_firmware
< 2013jun30a
Published
Jan 07, 2014
Tracked Since
Feb 18, 2026