CVE-2023-25100: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the vtyshubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the setqos function with the defaultclass variable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25100?
CVE-2023-25100 is a vulnerability that exists in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 firmware due to the use of an unsafe sprintf pattern, which can lead to arbitrary code execution.
How does CVE-2023-25100 affect Milesight UR32L firmware?
CVE-2023-25100 affects Milesight UR32L firmware version 32.3.0.5 by introducing multiple buffer overflow vulnerabilities in the vtysh_ubus binary.
What is the severity of CVE-2023-25100?
CVE-2023-25100 has a severity rating of 7.2 (High).
How can an attacker exploit CVE-2023-25100?
An attacker with high privileges can exploit CVE-2023-25100 by sending a specially crafted HTTP request to the vulnerable system, leading to arbitrary code execution.
Is Milesight UR32L software vulnerable to CVE-2023-25100?
Yes, Milesight UR32L firmware version 32.3.0.5 is vulnerable to CVE-2023-25100.