CVE-2023-22659: Command Injection
Published Jul 6, 2023
·Updated
An os command injection vulnerability exists in the libzebra.so changehostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Affected Software
2 affected components
Milesight Ur32l Firmware=32.3.0.5
Milesight UR32L
Event History
Jul 6, 2023
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-22659?
CVE-2023-22659 has a high severity due to its potential for remote command execution.
2
How do I fix CVE-2023-22659?
To mitigate CVE-2023-22659, upgrade the Milesight UR32L firmware to version 32.3.0.6 or later.
3
What systems are affected by CVE-2023-22659?
CVE-2023-22659 specifically affects Milesight UR32L devices running firmware version 32.3.0.5.
4
What type of vulnerability is CVE-2023-22659?
CVE-2023-22659 is classified as an OS command injection vulnerability.
5
What exploitation method is used in CVE-2023-22659?
CVE-2023-22659 can be exploited through specially-crafted network packets that trigger command execution.