Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the trace tool utility.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-28538 Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the trace tool utility.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-11-14T14:41:34.788Z

Reserved: 2023-01-25T15:05:01.030Z

Link: CVE-2023-24520

cve-icon Vulnrichment

Updated: 2024-08-02T10:56:04.274Z

cve-icon NVD

Status : Modified

Published: 2023-07-06T15:15:12.180

Modified: 2024-11-21T07:48:02.567

Link: CVE-2023-24520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.