CVE-2023-25101: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the vtyshubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the setdmvpn function with the grekey variable.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for these buffer overflow vulnerabilities?
The vulnerability ID for these buffer overflow vulnerabilities is CVE-2023-25101.
What is the severity rating of CVE-2023-25101?
CVE-2023-25101 has a severity rating of 7.2 (High).
What is the affected software by CVE-2023-25101?
The affected software by CVE-2023-25101 is Milesight UR32L v32.3.0.5 firmware.
How can the buffer overflow vulnerabilities be exploited?
The buffer overflow vulnerabilities can be exploited by sending a specially crafted HTTP request.
Is there a fix available for CVE-2023-25101?
Please refer to the reference link for information on available fixes for CVE-2023-25101.