PT-2023-18721 · Milesight · Milesight Vpn

Francesco Benvenuto

·

Published

2023-07-06

·

Updated

2023-07-13

·

CVE-2023-22844

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Milesight VPN version 2.0.2
Description An authentication bypass issue exists in the requestHandlers.js verifyToken functionality. A specially-crafted network request can lead to authentication bypass, allowing an attacker to send a network request and trigger this issue.
Recommendations For Milesight VPN version 2.0.2, consider disabling the verifyToken functionality in requestHandlers.js as a temporary workaround until a patch is available. Restrict access to the verifyToken function to minimize the risk of exploitation. Avoid using the verifyToken functionality in the affected API endpoint until the issue is resolved.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-22844

Affected Products

Milesight Vpn