CVE-2023-22306: Command Injection
Published Jul 6, 2023
·Updated
An OS command injection vulnerability exists in the libzebra.so bridgegroup functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Affected Software
2 affected components
Milesight Ur32l Firmware=32.3.0.5
Milesight UR32L
Event History
Jul 6, 2023
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-22306?
CVE-2023-22306 has been assigned a critical severity rating due to its potential for remote command execution.
2
How do I fix CVE-2023-22306?
To fix CVE-2023-22306, upgrade the Milesight UR32L firmware to version 32.3.0.6 or later.
3
What software is affected by CVE-2023-22306?
CVE-2023-22306 affects Milesight UR32L running firmware version 32.3.0.5.
4
Can CVE-2023-22306 be exploited remotely?
Yes, CVE-2023-22306 can be exploited remotely through specially crafted network packets.
5
What type of vulnerability is CVE-2023-22306?
CVE-2023-22306 is classified as an OS command injection vulnerability.