Milesight是中国星纵物联(Milesight)公司的一个完整的人工智能视频监控解决方案。 Milesight UR5X、UR32L、UR32、UR35、UR41 、Industrial Cellular Routers v35.3.0.7 之前版本存在日志信息泄露漏洞,该漏洞源于允许攻击者访问敏感路由器组件。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption | https://github.com/win3zz/CVE-2023-43261 | POC详情 |
| 2 | A critical security vulnerability has been identified in Milesight Industrial Cellular Routers, compromising the security of sensitive credentials and permitting unauthorized access. This vulnerability stems from a misconfiguration that results in directory listing being enabled on the router systems, rendering log files publicly accessible. These log files, while containing sensitive information such as admin and other user passwords (encrypted as a security measure), can be exploited by attackers via the router's web interface. The presence of a hardcoded AES secret key and initialization vector (IV) in the JavaScript code further exacerbates the situation, facilitating the decryption of these passwords. This chain of vulnerabilities allows malicious actors to gain unauthorized access to the router. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-43261.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2023-22618 | 8.1 HIGH | Nokia WaveLite 安全漏洞 |
| CVE-2023-3361 | 7.7 HIGH | Red Hat OpenShift 安全漏洞 |
| CVE-2023-1832 | 6.8 MEDIUM | Candlepin 安全漏洞 |
| CVE-2022-4132 | 5.9 MEDIUM | Apache Tomcat 安全漏洞 |
| CVE-2023-3153 | 5.3 MEDIUM | Open Virtual Network 安全漏洞 |
| CVE-2023-43838 | Personal Management System 代码问题漏洞 | |
| CVE-2023-27121 | Pleasant Solutions Pleasant Password Server 跨站脚本漏洞 | |
| CVE-2023-36619 | Atos Unify OpenScape 输入验证错误漏洞 | |
| CVE-2023-36618 | Atos Unify OpenScape 操作系统命令注入漏洞 | |
| CVE-2023-44075 | PHPGurukul Small CRM 跨站脚本漏洞 | |
| CVE-2023-43877 | RiteCMS 跨站脚本漏洞 | |
| CVE-2023-43321 | Digital China Networks DCFW-1800-SDC 代码问题漏洞 | |
| CVE-2023-40299 | Insomnia 安全漏洞 | |
| CVE-2023-35803 | Extreme Networks IQ Engine 安全漏洞 |
暂无评论