CVE-2023-0321 - CVE House
Back to Database
Status published Critical CVE-2023-0321

Disclosure of Sensitive Information on Campbell Scientific Products

Vulnerability Description

Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to download configuration files, which may contain sensitive information about the internal network. From factory defaults, the mentioned datalogges have HTTP and PakBus enabled. The devices, with the default configuration, allow this situation via the PakBus port. The exploitation of this vulnerability may allow an attacker to download, modify, and upload new configuration files.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-0321

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Carlos Antonini Cepeda

Affected Vendor

Campbell Scientific

View all reports →

Affected Software

CR6, CR300, CR800, CR1000, CR3000
Vulnerable Versions:
all version

Timeline

Official Publish: January 25th, 2023
Last Modified: March 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)