milesight kayıtları
milesight üreticisine ait 89 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-121 Stack-based Buffer Overflow46
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')8
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-798 Use of Hard-coded Credentials3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
89 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2023-43261Kavram kanıtı | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router componentsmilesight · ur5x firmware · CWE-532 | Yüksek7,5 | — | %59,6 | 4 Eki 2023 |
40Planlayın | CVE-2016-2356İstismar yok | Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.milesight · ip security camera firmware · CWE-120 | Kritik9,8 | — | %3,2 | 25 Eki 2019 |
40Planlayın | CVE-2016-2359İstismar yok | Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultanmilesight · ip security camera firmware · CWE-287 | Kritik9,8 | — | %3,1 | 25 Eki 2019 |
40Planlayın | CVE-2023-23902İstismar yok | A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-121 | Kritik9,8 | — | %2,2 | 6 Tem 2023 |
40Planlayın | CVE-2016-2357İstismar yok | Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.milesight · ip security camera firmware · CWE-798 | Kritik9,8 | — | %2,1 | 25 Eki 2019 |
40Planlayın | CVE-2016-2360İstismar yok | Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' inmilesight · ip security camera firmware · CWE-798 | Kritik9,8 | — | %2,1 | 25 Eki 2019 |
40Planlayın | CVE-2016-2358İstismar yok | Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials.milesight · ip security camera firmware · CWE-798 | Kritik9,8 | — | %2,1 | 25 Eki 2019 |
39İzleyin | CVE-2023-30466İstismar yok | Authentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)milesight · ms-n5008-uc firmware · CWE-640 | Kritik9,8 | — | %1,1 | 28 Nis 2023 |
39İzleyin | CVE-2023-30467İstismar yok | Improper Authorization Vulnerability in Milesight Network Video Recorder (NVR)milesight · ms-n5008-uc firmware · CWE-285 | Kritik9,8 | — | %1,1 | 28 Nis 2023 |
39İzleyin | CVE-2023-22319İstismar yok | A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2.milesight · milesightvpn · CWE-89 | Kritik9,8 | — | %0,9 | 6 Tem 2023 |
39İzleyin | CVE-2023-22844İstismar yok | An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2.milesight · milesightvpn · CWE-321 | Kritik9,8 | — | %0,8 | 6 Tem 2023 |
39İzleyin | CVE-2024-27776İstismar yok | MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')milesight · devicehub · CWE-22 | Kritik9,8 | — | %0,6 | 2 Haz 2024 |
39İzleyin | CVE-2023-32220İstismar yok | Milesight NCR/Camera Authentication Bypassmilesight · ncr\/camera firmware · CWE-287 | Kritik9,8 | — | %0,6 | 12 Haz 2023 |
39İzleyin | CVE-2024-36389İstismar yok | MileSight DeviceHub - CWE-330 Use of Insufficiently Random Valuesmilesight · devicehub · CWE-330 | Kritik9,8 | — | %0,5 | 2 Haz 2024 |
39İzleyin | CVE-2024-36388İstismar yok | MileSight DeviceHub - CWE-305 Missing Authentication for Critical Functionmilesight · devicehub · CWE-305 | Kritik9,8 | — | %0,5 | 2 Haz 2024 |
37İzleyin | CVE-2023-22653İstismar yok | An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-78 | Yüksek8,8 | — | %5,8 | 6 Tem 2023 |
36İzleyin | CVE-2023-22299İstismar yok | An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-78 | Yüksek8,8 | — | %3,6 | 6 Tem 2023 |
36İzleyin | CVE-2023-24519İstismar yok | Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-77 | Yüksek8,8 | — | %3,6 | 6 Tem 2023 |
36İzleyin | CVE-2023-24520İstismar yok | Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-77 | Yüksek8,8 | — | %3,6 | 6 Tem 2023 |
36İzleyin | CVE-2023-24582İstismar yok | Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-77 | Yüksek8,8 | — | %3,0 | 6 Tem 2023 |
36İzleyin | CVE-2023-24583İstismar yok | Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-77 | Yüksek8,8 | — | %3,0 | 6 Tem 2023 |
35İzleyin | CVE-2023-24018İstismar yok | A stack-based buffer overflow vulnerability exists in the libzebra.so.0.0.0 security_decrypt_password functionality of Milesight UR32L v32.3milesight · ur32l firmware · CWE-121 | Yüksek8,8 | — | %1,5 | 6 Tem 2023 |
35İzleyin | CVE-2023-47166İstismar yok | A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2.milesight · ur32l firmware · CWE-285 | Yüksek8,8 | — | %0,6 | 1 May 2024 |
33İzleyin | CVE-2023-22371İstismar yok | An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2.milesight · milesightvpn · CWE-77 | Yüksek8,1 | — | %3,4 | 6 Tem 2023 |
32İzleyin | CVE-2023-24019İstismar yok | A stack-based buffer overflow vulnerability exists in the urvpn_client http_connection_readcb functionality of Milesight UR32L v32.3.0.5.milesight · ur32l firmware · CWE-120 | Yüksek8,1 | — | %1,0 | 6 Tem 2023 |
- CVE-2023-4326148Planlayın
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components
YüksekCVSS 7,5Kavram kanıtıEPSS %60milesight · ur5x firmware4 Eki 2023
- CVE-2016-235640Planlayın
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
KritikCVSS 9,8İstismar yokEPSS %3milesight · ip security camera firmware25 Eki 2019
- CVE-2016-235940Planlayın
Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultan
KritikCVSS 9,8İstismar yokEPSS %3milesight · ip security camera firmware25 Eki 2019
- CVE-2023-2390240Planlayın
A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5.
KritikCVSS 9,8İstismar yokEPSS %2milesight · ur32l firmware6 Tem 2023
- CVE-2016-235740Planlayın
Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
KritikCVSS 9,8İstismar yokEPSS %2milesight · ip security camera firmware25 Eki 2019
- CVE-2016-236040Planlayın
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' in
KritikCVSS 9,8İstismar yokEPSS %2milesight · ip security camera firmware25 Eki 2019
- CVE-2016-235840Planlayın
Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials.
KritikCVSS 9,8İstismar yokEPSS %2milesight · ip security camera firmware25 Eki 2019
- CVE-2023-3046639İzleyin
Authentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)
KritikCVSS 9,8İstismar yokEPSS %1milesight · ms-n5008-uc firmware28 Nis 2023
- CVE-2023-3046739İzleyin
Improper Authorization Vulnerability in Milesight Network Video Recorder (NVR)
KritikCVSS 9,8İstismar yokEPSS %1milesight · ms-n5008-uc firmware28 Nis 2023
- CVE-2023-2231939İzleyin
A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2.
KritikCVSS 9,8İstismar yokEPSS %1milesight · milesightvpn6 Tem 2023
- CVE-2023-2284439İzleyin
An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2.
KritikCVSS 9,8İstismar yokEPSS %1milesight · milesightvpn6 Tem 2023
- CVE-2024-2777639İzleyin
MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
KritikCVSS 9,8İstismar yokEPSS %1milesight · devicehub2 Haz 2024
- CVE-2023-3222039İzleyin
Milesight NCR/Camera Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %1milesight · ncr\/camera firmware12 Haz 2023
- CVE-2024-3638939İzleyin
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values
KritikCVSS 9,8İstismar yokEPSS %1milesight · devicehub2 Haz 2024
- CVE-2024-3638839İzleyin
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
KritikCVSS 9,8İstismar yokEPSS %0milesight · devicehub2 Haz 2024
- CVE-2023-2265337İzleyin
An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5.
YüksekCVSS 8,8İstismar yokEPSS %6milesight · ur32l firmware6 Tem 2023
- CVE-2023-2229936İzleyin
An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5.
YüksekCVSS 8,8İstismar yokEPSS %4milesight · ur32l firmware6 Tem 2023
- CVE-2023-2451936İzleyin
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5.
YüksekCVSS 8,8İstismar yokEPSS %4milesight · ur32l firmware6 Tem 2023
- CVE-2023-2452036İzleyin
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5.
YüksekCVSS 8,8İstismar yokEPSS %4milesight · ur32l firmware6 Tem 2023
- CVE-2023-2458236İzleyin
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5.
YüksekCVSS 8,8İstismar yokEPSS %3milesight · ur32l firmware6 Tem 2023
- CVE-2023-2458336İzleyin
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5.
YüksekCVSS 8,8İstismar yokEPSS %3milesight · ur32l firmware6 Tem 2023
- CVE-2023-2401835İzleyin
A stack-based buffer overflow vulnerability exists in the libzebra.so.0.0.0 security_decrypt_password functionality of Milesight UR32L v32.3
YüksekCVSS 8,8İstismar yokEPSS %1milesight · ur32l firmware6 Tem 2023
- CVE-2023-4716635İzleyin
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2.
YüksekCVSS 8,8İstismar yokEPSS %1milesight · ur32l firmware1 May 2024
- CVE-2023-2237133İzleyin
An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2.
YüksekCVSS 8,1İstismar yokEPSS %3milesight · milesightvpn6 Tem 2023
- CVE-2023-2401932İzleyin
A stack-based buffer overflow vulnerability exists in the urvpn_client http_connection_readcb functionality of Milesight UR32L v32.3.0.5.
YüksekCVSS 8,1İstismar yokEPSS %1milesight · ur32l firmware6 Tem 2023