CVE-2023-24595: OS Command Injection
An OS command injection vulnerability exists in the ysthirdparty systemuserscript functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24595?
CVE-2023-24595 is an OS command injection vulnerability that exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5.
How severe is CVE-2023-24595?
CVE-2023-24595 has a severity rating of 7.2, which is considered high.
How does CVE-2023-24595 work?
CVE-2023-24595 can be exploited by sending a specially crafted series of network requests to the ys_thirdparty system_user_script functionality, which can lead to command execution.
Which software versions are affected by CVE-2023-24595?
Milesight UR32L v32.3.0.5 is affected by CVE-2023-24595.
How can I fix the OS command injection vulnerability in Milesight UR32L v32.3.0.5?
To fix the OS command injection vulnerability, it is recommended to update Milesight UR32L firmware to a version that is not affected, if available.