CVE-2023-30467: Improper Authorization Vulnerability in Milesight Network Video Recorder (NVR)
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.
Successful exploitation of this vulnerability could allow remote attacker to perform unauthorized activities on the targeted device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-30467?
CVE-2023-30467 is a vulnerability that exists in Milesight 4K/H.265 Series NVR models due to improper authorization at the Milesight NVR web-based management interface.
What is the severity of CVE-2023-30467?
The severity of CVE-2023-30467 is critical with a CVSS score of 9.8.
How does CVE-2023-30467 affect Milesight 4K/H.265 Series NVR models?
CVE-2023-30467 affects Milesight 4K/H.265 Series NVR models by allowing remote attackers to exploit the vulnerability through the web-based management interface.
Which software versions are affected by CVE-2023-30467?
CVE-2023-30467 affects Milesight 4K/H.265 Series NVR models with firmware versions up to and including 77.9.0.18-r2.
Where can I find more information about CVE-2023-30467?
You can find more information about CVE-2023-30467 at the CERT-IN website.