CVE-2023-25092: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the vtyshubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the handleinterfaceacl function with the interface and outacl variables.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25092.
What is the severity of CVE-2023-25092?
The severity of CVE-2023-25092 is high (7.2).
What is the affected software?
The affected software is Milesight UR32L v32.3.0.5.
How does CVE-2023-25092 occur?
CVE-2023-25092 occurs due to multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L v32.3.0.5.
How can CVE-2023-25092 be exploited?
CVE-2023-25092 can be exploited by sending a specially crafted HTTP request, leading to arbitrary code execution.