NA

CVE-2023-30466

Published: 28/04/2023 Updated: 05/05/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device. Successful exploitation of this vulnerability could allow remote malicious user to account takeover on the targeted device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

milesight ms-n5008-uc_firmware

milesight ms-n1008-unc_firmware

milesight ms-n1008-uc_firmware

milesight ms-n1004-uc_firmware

milesight ms-n5016-e_firmware

milesight ms-n5008-e_firmware

milesight ms-n7016-uh_firmware

milesight ms-n7032-uh_firmware

milesight ms-n8064-uh_firmware

milesight ms-n8032-uh_firmware

milesight ms-n1004-upc_firmware

milesight ms-n1008-upc_firmware

milesight ms-n1008-unpc_firmware

milesight ms-n5008-upc_firmware

milesight ms-n5016-pe_firmware

milesight ms-n5008-pe_firmware

milesight ms-n7016-uph_firmware

milesight ms-n7032-uph_firmware

milesight ms-n7048-uph_firmware

milesight ms-nxxxx-xxg firmware

milesight ms-nxxxx-xxt firmware