CVE-2023-22653: OS Command Injection
Published Jul 6, 2023
·Updated
An OS command injection vulnerability exists in the vtyshubus tcpdumpstartcb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An authenticated attacker can send an HTTP request to trigger this vulnerability.
Affected Software
2 affected components
Milesight Ur32l Firmware=32.3.0.5
Milesight UR32L
Event History
Jul 6, 2023
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-22653?
CVE-2023-22653 is an OS command injection vulnerability in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5.
2
What is the severity of CVE-2023-22653?
CVE-2023-22653 has a severity rating of 8.8 (high).
3
How does CVE-2023-22653 affect Milesight UR32L v32.3.0.5?
CVE-2023-22653 can allow an authenticated attacker to execute arbitrary commands through a specially crafted HTTP request.
4
Is Milesight UR32L vulnerable to CVE-2023-22653?
Yes, Milesight UR32L v32.3.0.5 is vulnerable to CVE-2023-22653.
5
How can I fix CVE-2023-22653?
To fix CVE-2023-22653, apply the latest firmware update provided by Milesight for UR32L v32.3.0.5.