Vulnerabilities > Milesight > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-06 CVE-2023-25123 Out-of-bounds Write vulnerability in Milesight Ur32L Firmware 32.3.0.5
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern.
network
low complexity
milesight CWE-787
7.2
2023-07-06 CVE-2023-25124 Out-of-bounds Write vulnerability in Milesight Ur32L Firmware 32.3.0.5
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern.
network
low complexity
milesight CWE-787
7.2
2023-07-06 CVE-2023-25582 Unspecified vulnerability in Milesight Ur32L Firmware 32.3.0.5
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5.
network
low complexity
milesight
7.2
2023-07-06 CVE-2023-25583 Unspecified vulnerability in Milesight Ur32L Firmware 32.3.0.5
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5.
network
low complexity
milesight
7.2
2023-05-08 CVE-2023-24505 Unspecified vulnerability in Milesight Ncr/Camera Firmware 71.8.0.6R5
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
network
low complexity
milesight
7.5
2023-05-08 CVE-2023-24506 Insufficiently Protected Credentials vulnerability in Milesight Ncr/Camera Firmware 71.8.0.6R5
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
network
low complexity
milesight CWE-522
7.5
2022-09-15 CVE-2022-3001 Improper Input Validation vulnerability in Milesight Video Management Systems Firmware 40.7.0.79
This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface.
network
low complexity
milesight CWE-20
7.5