CVE-2023-25105: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the vtyshubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the setikeprofile function with the secretsremote variable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25105?
CVE-2023-25105 is a vulnerability in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 firmware that allows arbitrary code execution through a specially crafted HTTP request.
How does CVE-2023-25105 occur?
CVE-2023-25105 occurs due to multiple buffer overflow vulnerabilities in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 firmware caused by the use of an unsafe sprintf pattern.
What is the severity of CVE-2023-25105?
CVE-2023-25105 has a severity rating of 7.2 out of 10, which is classified as high.
How can an attacker exploit CVE-2023-25105?
An attacker with high privileges can exploit CVE-2023-25105 by sending a specially crafted HTTP request to trigger the buffer overflow vulnerabilities and gain arbitrary code execution.
Is Milesight UR32L firmware version 32.3.0.5 affected by CVE-2023-25105?
Yes, Milesight UR32L firmware version 32.3.0.5 is affected by CVE-2023-25105.