VDB
CVE-2023-30801
CVE-2023-30801
PUBLISHED
CVSS 9.800000190734863 CRITICAL
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.
EPSS 0.91% · 57.5th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.91%
57.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| qBittorrent | qBittorrent client | 0, 0 |
| qbittorrent | qbittorrent | 0, 0, 0 |
Timeline
- Oct 10, 2023 CVE Published
- Oct 10, 2023 PoC Published
- Oct 11, 2023 EPSS Score
- Nov 12, 2023 EPSS Score
- Dec 13, 2023 EPSS Score
- Feb 15, 2024 EPSS Score
- Mar 17, 2024 EPSS Score
- Apr 18, 2024 EPSS Score
- May 20, 2024 EPSS Score
- Jul 22, 2024 EPSS Score
- Aug 23, 2024 EPSS Score
- Sep 23, 2024 EPSS Score
References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4BNFJR3ZWVLE2YSYIQYBWVDQBBZOLEL/ url
- https://github.com/qbittorrent/qBittorrent/issues/18731 issue
- https://nvd.nist.gov/vuln/detail/CVE-2023-30801 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T5WXBKELVZFZNIDONIJESOCSRPIQNCGI/ url
- https://vulncheck.com/advisories/qbittorrent-default-creds third-party-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T5WXBKELVZFZNIDONIJESOCSRPIQNCGI url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4BNFJR3ZWVLE2YSYIQYBWVDQBBZOLEL url