4 ms·
I was very confused by the date format, so here's the timeline with ISO dates: Vulnerability found, 2022-11-08 Sent detailed PoC, 2022-11-09 RIGOL says they
by hadrien01 3y ago
I was very confused by the date format, so here's the timeline with ISO dates:
Vulnerability found, 2022-11-08
Sent detailed PoC, 2022-11-09
RIGOL says they would have contacted me with updates from R&D, 2022-11-09
Follow-up on the vulnerability, 2023-01-25
RIGOL says they would reply in 2-3 days, 2023-01-28
Full disclosure, 2023-02-08
- stavros 3y agoDoes this mean they never patched this, then?
- psychphysic 3y agoSo odd to list a timeline but not enough detail to work out what happened.
- ericpauley 3y agoSuch is life with CVEs, unfortunately. While there are some great central repositories of information there is often very little in the way of consistent information on the disclosure process itself.
- Eduard 3y agoIt's pretty clear to work out what happened from the timeline listed: RIGOL didn’t do shit. The style the author chose to list the timeline is IMHO the most faithful, honest, and polite way of communicating it without adding wrong or legally problematic reasoning to the situation, from their perspective.
- psychphysic 3y agoNah, "no response received from RIGOL" if that's the case is faithful, honest and polite.
- jjoonathan 3y agoThis is RIGOL we are talking about. In a year, they will release a firmware that solves the RCE but opens two more and also breaks cursors (or some other very basic thing). A year after that, they will release a second firmware that fixes the cursors but breaks the calibration and still has the two new RCEs.
- anitil 3y agoIn my experience this is most firmware vendors
- mensi 3y agoI actually reported the same pair of bugs to them 2021-03-01, so I don't think they're interested in fixing it...