First published: Thu Jul 06 2023(Updated: )
An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to command execution. An attacker can send a malicious packet to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Milesight Milesightvpn | =2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22371 is rated as a critical severity vulnerability due to its potential for command execution.
To fix CVE-2023-22371, upgrade to a patched version of Milesight VPN that addresses this vulnerability.
CVE-2023-22371 affects Milesight VPN version 2.0.2 specifically.
CVE-2023-22371 is an OS command injection vulnerability.
An attacker can exploit CVE-2023-22371 by sending a specially-crafted network request that leads to command execution.