CVE-2023-30466
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.
Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.
Affected (21)
Products: Milesight: Ms N5008 Uc Firmware, Ms N1008 Unc Firmware, Ms N1008 Uc Firmware, Ms N1004 Uc Firmware, Ms N5016 E Firmware, Ms N5008 E Firmware, Ms N7016 Uh Firmware, Ms N7032 Uh Firmware, Ms N8064 Uh Firmware, Ms N8032 Uh Firmware, Ms N1004 Upc Firmware, Ms N1008 Upc Firmware, Ms N1008 Unpc Firmware, Ms N5008 Upc Firmware, Ms N5016 Pe Firmware, Ms N5008 Pe Firmware, Ms N7016 Uph Firmware, Ms N7032 Uph Firmware, Ms N7048 Uph Firmware, Ms Nxxxx Xxg Firmware, Ms Nxxxx Xxt Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N5008 Uc | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N1008 Unc | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N1008 Uc | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N1004 Uc | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 75.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N5016 E | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 75.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N5008 E | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N7016 Uh | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N7032 Uh | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N8064 Uh | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N8032 Uh | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N1004 Upc | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N1008 Upc | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N1008 Unpc | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 73.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N5008 Upc | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 75.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N5016 Pe | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 75.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N5008 Pe | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N7016 Uph | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N7032 Uph | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 71.9.0.18-r2 |
| Running on/with | Platform Versions |
|---|---|
Milesight Ms N7048 Uph | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 77.9.0.18-r2 | |
| Before 72.9.0.18-r2 |
References (2)
Source: vdisclose@cert-in.org.in
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.