CVE-2024-5947 is an authentication bypass vulnerability in Deep Sea Electronics DSE855 devices, specifically within the web-based UI of the DSE855 and its firmware. This flaw allows network-adjacent attackers to disclose sensitive information, including stored credentials, without requiring any authentication. Rated with a CVSS score of 6.5 (Medium), the vulnerability has a high confidentiality impact (C:H) due to the potential for credential disclosure, with low attack complexity and no user interaction required. While there is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, Nuclei templates exist for this authentication bypass, and it has a high EPSS score and FAUCET Risk Score, indicating a significant potential for exploitation. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0CPE matchmatch criteria | cpe:2.3:o:deepseaelectronics:dse855_firmware:1.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.