CVE-2023-24506: Milesight NCR/Camera CWE-522: Insufficiently Protected Credentials
Published May 8, 2023
·Updated
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
Affected Software
4 affected components
Milesight Ncr\/camera Firmware=71.8.0.6-r5
Milesight Ncr\/camera
All of the following
Milesight Ncr\/camera Firmware=71.8.0.6-r5
Milesight Ncr\/camera
Event History
May 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
09:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-24506?
CVE-2023-24506 has a high severity rating due to the exposure of credentials.
2
How do I fix CVE-2023-24506?
To fix CVE-2023-24506, upgrade to the latest version of Milesight NCR/camera firmware that addresses this vulnerability.
3
What specific version of the Milesight NCR/camera firmware is affected by CVE-2023-24506?
CVE-2023-24506 affects Milesight NCR/camera firmware version 71.8.0.6-r5.
4
Are there any known exploits for CVE-2023-24506?
Yes, CVE-2023-24506 has been reported to be exploitable, making it critical to address.
5
What type of information is exposed in CVE-2023-24506?
CVE-2023-24506 exposes sensitive credentials through an unspecified request.