VDB
CVE-2023-30801
CVE-2023-30801
PUBLISHED
CVSS 9.800000190734863 CRITICAL
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials to authenticate and execute arbitrary operating system commands using the "external program" feature in the web user interface. This was reportedly exploited in the wild in March 2023.
EPSS 0.63% · 70.6th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.63%
70.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| qBittorrent | qBittorrent client | 0, 0 |
| qbittorrent | qbittorrent | 0, 0, 0 |
Exploit Intelligence
- CIRCL exploited: CVE-2023-30801 (circl-sighting)
- https://github.com/qbittorrent/qBittorrent/issues/18731 (circl)
- https://vulncheck.com/advisories/qbittorrent-default-creds (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T5WXBKELVZFZNIDONIJESOCSRPIQNCGI/ (circl)
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4BNFJR3ZWVLE2YSYIQYBWVDQBBZOLEL/ (circl)
Timeline
- Oct 10, 2023 CVE Published
- Oct 10, 2023 PoC Published
- Oct 11, 2023 EPSS Score
- Nov 11, 2023 EPSS Score
- Dec 13, 2023 EPSS Score
- Feb 14, 2024 EPSS Score
- Mar 16, 2024 EPSS Score
- Apr 17, 2024 EPSS Score
- May 18, 2024 EPSS Score
- Jun 19, 2024 EPSS Score
- Aug 20, 2024 EPSS Score
- Sep 21, 2024 EPSS Score
References
- https://github.com/qbittorrent/qBittorrent/issues/18731 issue
- https://vulncheck.com/advisories/qbittorrent-default-creds third-party-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T5WXBKELVZFZNIDONIJESOCSRPIQNCGI/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4BNFJR3ZWVLE2YSYIQYBWVDQBBZOLEL/ url
- https://nvd.nist.gov/vuln/detail/CVE-2023-30801 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T5WXBKELVZFZNIDONIJESOCSRPIQNCGI url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U4BNFJR3ZWVLE2YSYIQYBWVDQBBZOLEL url