Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpv9-5pvw-6mc2

Опубликовано: 28 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.

Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.

This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.

Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.

EPSS

Процентиль: 78%
0.01131
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device. Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.

CVSS3: 9.8
fstec
почти 3 года назад

Уязвимость механизма сброса пароля в веб-интерфейсе управления Milesight NVR микропрограммного обеспечения сетевых видеорегистраторов Milesight, позволяющая нарушителю получить несанкционированный доступ к устройству

EPSS

Процентиль: 78%
0.01131
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-640