CVE-2022-3001: Vulnerability in Milesight Video Management Systems (VMS)
This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera. Successful exploitation of this vulnerability could allow the attacker to cause a Denial of Service condition on the targeted device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3001?
The severity of CVE-2022-3001 is considered to be high due to the potential for remote exploitation.
How do I fix CVE-2022-3001?
To fix CVE-2022-3001, update the Milesight Video Management Systems firmware to version 40.7.0.79 or later.
What types of attacks can exploit CVE-2022-3001?
CVE-2022-3001 can be exploited by sending specially crafted HTTP requests to the vulnerable web-based management interface.
Which products are affected by CVE-2022-3001?
CVE-2022-3001 affects all firmware versions of Milesight Video Management Systems prior to 40.7.0.79.
Is there a public exploit for CVE-2022-3001?
As of now, there is no known public exploit specifically listed for CVE-2022-3001.