CVE-2023-23546: High severity milesight ur32l firmware vulnerability
A misconfiguration vulnerability exists in the urvpnclient functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23546?
CVE-2023-23546 has been rated with a high severity due to its potential for privilege escalation through a man-in-the-middle attack.
How do I fix CVE-2023-23546?
To mitigate CVE-2023-23546, ensure that you update the Milesight UR32L firmware to version 32.3.0.6 or later.
What type of attack is associated with CVE-2023-23546?
CVE-2023-23546 is associated with a man-in-the-middle attack that exploits a misconfiguration in the urvpn_client functionality.
Which version of Milesight UR32L is vulnerable to CVE-2023-23546?
The vulnerable version of Milesight UR32L is firmware version 32.3.0.5.
What impact does CVE-2023-23546 have on affected systems?
CVE-2023-23546 can lead to increased privileges for an attacker, potentially compromising the affected system.