CVE-2026-3356 Details
Description
The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management interface. Because the device provides no mechanism to enable or configure authentication, the issue is inherent to its design rather than a deployment error.
An authentication bypass vulnerability has been identified in the Anritsu Remote Spectrum Monitor model MS27102A. This flaw allows unauthorized users to access and manipulate the device's management interface. The vulnerability arises from the device's design, as it lacks any mechanism to enable or configure authentication, rather than being a result of deployment errors.
CISA recommends minimizing network exposure for all control system devices, ensuring they are not accessible from the Internet. It is advised to locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is necessary, use secure methods such as Virtual Private Networks (VPNs), while keeping in mind that VPNs may have vulnerabilities and should be updated to the latest version. Organizations should perform a proper impact analysis and risk assessment before deploying defensive measures.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | New CVE Received | [email protected] |