CVE-2023-22844: Critical severity milesight vpn vulnerability
Published Jul 6, 2023
·Updated
An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.
Affected Software
1 affected component
Milesight Milesightvpn=2.0.2
Event History
Jul 6, 2023
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-22844?
CVE-2023-22844 is classified as a critical severity authentication bypass vulnerability.
2
How do I fix CVE-2023-22844?
To fix CVE-2023-22844, upgrade Milesight VPN to version 2.0.3 or later.
3
What software is affected by CVE-2023-22844?
CVE-2023-22844 affects Milesight VPN version 2.0.2.
4
What is the impact of CVE-2023-22844?
The impact of CVE-2023-22844 can allow attackers to bypass authentication and potentially gain unauthorized access.
5
Can CVE-2023-22844 be exploited remotely?
Yes, CVE-2023-22844 can be exploited remotely through specially-crafted network requests.