CVE-2023-25097

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jul 6, 2023
Updated: Oct 30, 2023
CWE ID 787
CWE ID 121

Summary

CVE-2023-25097: A series of buffer overflow vulnerabilities have been discovered in the vtysh_ubus binary of Milesight UR32L v32.3.0.5. These vulnerabilities arise due to an unsafe usage of sprintf. A skilled adversary can exploit these flaws by crafting a malicious HTTP request, leading to arbitrary code execution. The affected function is set_qos, specifically the attach_class variable.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share