Vulnerabilities > Milesight > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-06 CVE-2023-25123 Out-of-bounds Write vulnerability in Milesight Ur32L Firmware 32.3.0.5
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern.
network
low complexity
milesight CWE-787
7.2
2023-07-06 CVE-2023-25124 Out-of-bounds Write vulnerability in Milesight Ur32L Firmware 32.3.0.5
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern.
network
low complexity
milesight CWE-787
7.2
2023-07-06 CVE-2023-25582 OS Command Injection vulnerability in Milesight Ur32L Firmware 32.3.0.5
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5.
network
low complexity
milesight CWE-78
7.2
2023-07-06 CVE-2023-25583 OS Command Injection vulnerability in Milesight Ur32L Firmware 32.3.0.5
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5.
network
low complexity
milesight CWE-78
7.2
2023-05-08 CVE-2023-24505 Unspecified vulnerability in Milesight Ncr/Camera Firmware 71.8.0.6R5
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
network
low complexity
milesight
7.5
2023-05-08 CVE-2023-24506 Insufficiently Protected Credentials vulnerability in Milesight Ncr/Camera Firmware 71.8.0.6R5
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
network
low complexity
milesight CWE-522
7.5
2019-10-25 CVE-2016-2359 Improper Authentication vulnerability in Milesight IP Security Camera Firmware
Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.
network
low complexity
milesight CWE-287
7.5
2019-10-25 CVE-2016-2356 Classic Buffer Overflow vulnerability in Milesight IP Security Camera Firmware
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
network
low complexity
milesight CWE-120
7.5