CVE-2023-24018

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jul 6, 2023
Updated: Oct 30, 2023
CWE ID 787
CWE ID 121

Summary

CVE-2023-24018 is a stack-based buffer overflow vulnerability affecting the libzebra.so.0.0.0 security_decrypt_password functionality in Milesight UR32L v32.3.0.5. An attacker, once authenticated, can exploit this flaw by sending a specially crafted HTTP request. Successful exploitation could result in arbitrary code execution or a denial-of-service condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share