Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the ping tool utility.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-28537 Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the ping tool utility.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-11-14T14:45:10.681Z

Reserved: 2023-01-25T15:05:01.029Z

Link: CVE-2023-24519

cve-icon Vulnrichment

Updated: 2024-08-02T10:56:04.281Z

cve-icon NVD

Status : Modified

Published: 2023-07-06T15:15:12.107

Modified: 2024-11-21T07:48:02.430

Link: CVE-2023-24519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.