Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28610 | An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 14 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-11-14T14:49:09.344Z
Reserved: 2023-01-27T18:05:46.317Z
Link: CVE-2023-24595
Updated: 2024-08-02T11:03:19.247Z
Status : Modified
Published: 2023-07-06T15:15:12.397
Modified: 2024-11-21T07:48:12.213
Link: CVE-2023-24595
No data.
OpenCVE Enrichment
No data.
EUVD