CVE-2023-24019: Buffer Overflow
Published Jul 6, 2023
·Updated
A stack-based buffer overflow vulnerability exists in the urvpnclient httpconnectionreadcb functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
Affected Software
2 affected components
Milesight Ur32l Firmware=32.3.0.5
Milesight UR32L
Event History
Jul 6, 2023
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-24019?
CVE-2023-24019 is a stack-based buffer overflow vulnerability in the urvpn_client http_connection_readcb functionality of Milesight UR32L v32.3.0.5.
2
What is the severity of CVE-2023-24019?
The severity of CVE-2023-24019 is high, with a severity value of 8.1.
3
How does CVE-2023-24019 affect Milesight UR32L firmware?
CVE-2023-24019 affects Milesight UR32L firmware version 32.3.0.5.
4
How can an attacker exploit CVE-2023-24019?
An attacker can exploit CVE-2023-24019 by sending a specially crafted network packet to trigger a stack-based buffer overflow.
5
Is Milesight UR32L vulnerable to CVE-2023-24019?
No, Milesight UR32L is not vulnerable to CVE-2023-24019.