PT-2023-4165 · Milesight · Milesight Ur32L

·

CVE-2023-23902

·

Publicado

2023-07-06

·

Atualizado

2023-08-06

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Milesight UR32L version 32.3.0.5
Description A buffer overflow vulnerability exists in the uhttpd login functionality, allowing remote code execution through a specially crafted network request. An attacker can exploit this issue by sending a malicious request.
Recommendations For Milesight UR32L version 32.3.0.5, consider disabling the uhttpd login functionality until a patch is available to prevent remote code execution. Restrict access to the login functionality to minimize the risk of exploitation.

Exploit

Correção

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04477
CVE-2023-23902

Produtos afetados

Milesight Ur32L