Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Milesight
Subscribe
|
Ms-n1004-uc
Subscribe
Ms-n1004-uc Firmware
Subscribe
Ms-n1004-upc
Subscribe
Ms-n1004-upc Firmware
Subscribe
Ms-n1008-uc
Subscribe
Ms-n1008-uc Firmware
Subscribe
Ms-n1008-unc
Subscribe
Ms-n1008-unc Firmware
Subscribe
Ms-n1008-unpc
Subscribe
Ms-n1008-unpc Firmware
Subscribe
Ms-n1008-upc
Subscribe
Ms-n1008-upc Firmware
Subscribe
Ms-n5008-e
Subscribe
Ms-n5008-e Firmware
Subscribe
Ms-n5008-pe
Subscribe
Ms-n5008-pe Firmware
Subscribe
Ms-n5008-uc
Subscribe
Ms-n5008-uc Firmware
Subscribe
Ms-n5008-upc
Subscribe
Ms-n5008-upc Firmware
Subscribe
Ms-n5016-e
Subscribe
Ms-n5016-e Firmware
Subscribe
Ms-n5016-pe
Subscribe
Ms-n5016-pe Firmware
Subscribe
Ms-n7016-uh
Subscribe
Ms-n7016-uh Firmware
Subscribe
Ms-n7016-uph
Subscribe
Ms-n7016-uph Firmware
Subscribe
Ms-n7032-uh
Subscribe
Ms-n7032-uh Firmware
Subscribe
Ms-n7032-uph
Subscribe
Ms-n7032-uph Firmware
Subscribe
Ms-n7048-uph
Subscribe
Ms-n7048-uph Firmware
Subscribe
Ms-n8032-uh
Subscribe
Ms-n8032-uh Firmware
Subscribe
Ms-n8064-uh
Subscribe
Ms-n8064-uh Firmware
Subscribe
Ms-nxxxx-xxg Firmware
Subscribe
Ms-nxxxx-xxt Firmware
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34881 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device. Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device. |
Solution
Update Milesight NVR firmware to latest version https://www.milesight.com/support/download/firmware https://www.milesight.com/support/download/firmware
Workaround
No workaround given by the vendor.
Thu, 30 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-In
Published:
Updated: 2025-01-30T17:16:05.788Z
Reserved: 2023-04-10T10:20:17.200Z
Link: CVE-2023-30466
Updated: 2024-08-02T14:28:50.581Z
Status : Modified
Published: 2023-04-28T11:15:08.987
Modified: 2024-11-21T08:00:14.443
Link: CVE-2023-30466
No data.
OpenCVE Enrichment
No data.
EUVD