Description
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.

Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.










Published: 2023-04-28
Score: 9.8 Critical
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Milesight NVR firmware to latest version   https://www.milesight.com/support/download/firmware https://www.milesight.com/support/download/firmware

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-34881 This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device. Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.
History

Thu, 30 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Milesight Ms-n1004-uc Ms-n1004-uc Firmware Ms-n1004-upc Ms-n1004-upc Firmware Ms-n1008-uc Ms-n1008-uc Firmware Ms-n1008-unc Ms-n1008-unc Firmware Ms-n1008-unpc Ms-n1008-unpc Firmware Ms-n1008-upc Ms-n1008-upc Firmware Ms-n5008-e Ms-n5008-e Firmware Ms-n5008-pe Ms-n5008-pe Firmware Ms-n5008-uc Ms-n5008-uc Firmware Ms-n5008-upc Ms-n5008-upc Firmware Ms-n5016-e Ms-n5016-e Firmware Ms-n5016-pe Ms-n5016-pe Firmware Ms-n7016-uh Ms-n7016-uh Firmware Ms-n7016-uph Ms-n7016-uph Firmware Ms-n7032-uh Ms-n7032-uh Firmware Ms-n7032-uph Ms-n7032-uph Firmware Ms-n7048-uph Ms-n7048-uph Firmware Ms-n8032-uh Ms-n8032-uh Firmware Ms-n8064-uh Ms-n8064-uh Firmware Ms-nxxxx-xxg Firmware Ms-nxxxx-xxt Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-In

Published:

Updated: 2025-01-30T17:16:05.788Z

Reserved: 2023-04-10T10:20:17.200Z

Link: CVE-2023-30466

cve-icon Vulnrichment

Updated: 2024-08-02T14:28:50.581Z

cve-icon NVD

Status : Modified

Published: 2023-04-28T11:15:08.987

Modified: 2024-11-21T08:00:14.443

Link: CVE-2023-30466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses