CVE-2023-40707 | Weak password requirements in OPTO 22 SNAP PAC S1 Built-in Web Server
There are no requirements for setting a complex password in the built-in web server of the SNAP PAC S1 Firmware version R10.3b, which could allow for a successful brute force attack if users don't set up complex credentials.
Conclusion & alert: CVE-2023-40707 is rated Moderate Risk (47.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.47%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2023-40707
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).