Aller au contenu

Fiche vulnérabilité

CVE-2023-30467 : faille critique milesight ms-n5008-uc firmware (CVSS 9.8)

Description

This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device. Successful exploitation of this vulnerability could allow remote attacker to perform unauthorized activities on the targeted device.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
28 avr. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • milesight ms-n5008-uc firmware
  • milesight ms-n1008-unc firmware
  • milesight ms-n1008-uc firmware
  • milesight ms-n1004-uc firmware
  • milesight ms-n5016-e firmware
  • milesight ms-n5008-e firmware
  • milesight ms-n7016-uh firmware
  • milesight ms-n7032-uh firmware
  • milesight ms-n8064-uh firmware
  • milesight ms-n8032-uh firmware
  • milesight ms-n1004-upc firmware
  • milesight ms-n1008-upc firmware
  • milesight ms-n1008-unpc firmware
  • milesight ms-n5008-upc firmware
  • milesight ms-n5016-pe firmware
  • milesight ms-n5008-pe firmware
  • milesight ms-n7016-uph firmware
  • milesight ms-n7032-uph firmware
  • milesight ms-n7048-uph firmware
  • milesight ms-nxxxx-xxg firmware

Références

Rechercher une autre vulnérabilité dans la base CVE