Siglent manufactures digital oscilloscopes and electronic test equipment, with its disclosed vulnerabilities concentrating in firmware for models in the SDS1000X-E series. The observed weakness classes reflect device configuration and communication validation issues typical of networked instrumentation hardware, including origin validation errors and firmware integrity concerns. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Siglent over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25366CRITICAL In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password. | Jun 16, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-25367CRITICAL Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server. | Jun 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-25368HIGH Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Incorrect Access Control. An unauthenticated attacker can overwrite firmnware. | Jun 14, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-25369HIGH Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS is vulnerable to Denial of Service on the user interface triggered by malformed SCPI command. | Jun 14, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Siglent.
Media articles that mention a CVE ID that affects a product developed by Siglent — matched by CVE ID, not by vendor name.