CVE-2016-2359: Critical severity milesight ip security camera firmware vulnerability
Published Oct 25, 2019
·Updated
Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.
Affected Software
2 affected components
Milesight Ip Security Camera Firmware<=2016-11-14
Milesight IP security camera
Event History
Oct 25, 2019
CVE Published
via MITRE·12:46 PM
Data Sourced
via MITRE·12:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-2359?
CVE-2016-2359 is classified as a high severity vulnerability due to its ability to allow remote attackers to bypass authentication.
2
How do I fix CVE-2016-2359?
To mitigate CVE-2016-2359, upgrade your Milesight IP security camera firmware to a version released after 2016-11-14.
3
What devices are affected by CVE-2016-2359?
CVE-2016-2359 affects Milesight IP security camera firmware versions up to and including 2016-11-14.
4
What type of attack is CVE-2016-2359 associated with?
CVE-2016-2359 is associated with remote authentication bypass attacks.
5
Can CVE-2016-2359 lead to unauthorized access?
Yes, CVE-2016-2359 can lead to unauthorized access to protected resources on vulnerable Milesight IP security cameras.