CVE-2023-30466: Authentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.
Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30466?
The severity of CVE-2023-30466 is considered to be high due to the potential for remote exploitation.
How can I fix CVE-2023-30466?
To fix CVE-2023-30466, update the firmware of your Milesight NVR to the latest version that addresses the weak password reset mechanism.
Which devices are affected by CVE-2023-30466?
CVE-2023-30466 affects multiple models of Milesight NVR, including the MS-N5008-UC, MS-N1008-UC, and MS-N1004-UC among others.
What type of vulnerability is CVE-2023-30466?
CVE-2023-30466 is a vulnerability associated with a weak password reset mechanism that can be exploited by remote attackers.
Can CVE-2023-30466 be exploited remotely?
Yes, CVE-2023-30466 can be exploited remotely, allowing attackers to gain unauthorized access to the affected devices.