Описание
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-43261
- https://github.com/win3zz/CVE-2023-43261
- https://medium.com/%40win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
- https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
- https://support.milesight-iot.com/support/home
- http://milesight.com
- http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html
- http://ur5x.com
Связанные уязвимости
CVSS3: 7.5
nvd
почти 3 года назад
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVSS3: 7.5
fstec
почти 3 года назад
Уязвимость микропрограммного обеспечения маршрутизаторов Milesight UR5X, UR32L, UR32, UR35, UR41, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации