Description
An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27650 | An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. |
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-02T10:35:32.712Z
Reserved: 2023-01-19T14:56:01.395Z
Link: CVE-2023-23550
Updated: 2024-08-02T10:35:32.712Z
Status : Modified
Published: 2023-07-06T15:15:11.497
Modified: 2024-11-21T07:46:24.110
Link: CVE-2023-23550
No data.
OpenCVE Enrichment
No data.
EUVD