CVE-2023-23902: Buffer Overflow
A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23902?
CVE-2023-23902 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2023-23902?
To mitigate CVE-2023-23902, update the Milesight UR32L firmware to the latest version that addresses this buffer overflow vulnerability.
What causes CVE-2023-23902?
CVE-2023-23902 is caused by a buffer overflow in the uhttpd login functionality of Milesight UR32L v32.3.0.5.
Is my device impacted by CVE-2023-23902?
Devices running Milesight UR32L with firmware version 32.3.0.5 are impacted by CVE-2023-23902.
Can CVE-2023-23902 lead to data breaches?
Yes, CVE-2023-23902 can lead to unauthorized remote access and potential data breaches if exploited by an attacker.