This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera. Successful exploitation of this vulnerability could allow the attacker to cause a Denial of Service condition on the targeted device.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-42440 | This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera. Successful exploitation of this vulnerability could allow the attacker to cause a Denial of Service condition on the targeted device. |
Fixes
Solution
Update Milesight VMS firmware to latest version https://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view?usp=sharing
Workaround
No workaround given by the vendor.
References
History
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2024-09-16T17:47:40.718Z
Reserved: 2022-08-26T00:00:00
Link: CVE-2022-3001

No data.

Status : Modified
Published: 2022-09-15T15:15:10.400
Modified: 2024-11-21T07:18:37.093
Link: CVE-2022-3001

No data.

No data.