CVE-2024-36389: MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values
Published Jun 2, 2024
·Updated
MileSight DeviceHub -
CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
Affected Software
2 affected components
All of the following
Milesight DeviceHub=3.0.1-r1
Ubuntu=20.04
Event History
Jun 2, 2024
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36389?
CVE-2024-36389 is classified as having a medium severity level due to the potential for authentication bypass.
2
How do I fix CVE-2024-36389?
To fix CVE-2024-36389, update MileSight DeviceHub to the latest version that addresses this vulnerability.
3
What impact does CVE-2024-36389 have on MileSight DeviceHub?
CVE-2024-36389 can allow unauthorized users to bypass authentication, leading to unauthorized access to the device.
4
Which versions of MileSight DeviceHub are affected by CVE-2024-36389?
MileSight DeviceHub version 3.0.1-r1 is affected by CVE-2024-36389.
5
Are there any operating systems vulnerable to CVE-2024-36389?
CVE-2024-36389 specifically affects MileSight DeviceHub and is not directly associated with vulnerabilities in Ubuntu.