2023-04-28 14:00:26 +02:00
{
"id" : "CVE-2023-30467" ,
"sourceIdentifier" : "vdisclose@cert-in.org.in" ,
"published" : "2023-04-28T11:15:09.040" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:00:14.600" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-28 14:00:26 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.\n\nSuccessful exploitation of this vulnerability could allow remote attacker to perform unauthorized activities on the targeted device.\n\n\n\n\n\n\n\n\n\n\n"
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-05-05 20:00:27 +02:00
{
2024-12-08 03:06:42 +00:00
"source" : "vdisclose@cert-in.org.in" ,
"type" : "Secondary" ,
2023-05-05 20:00:27 +02:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH" ,
2023-05-05 20:00:27 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
2024-12-08 03:06:42 +00:00
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH"
2023-05-05 20:00:27 +02:00
} ,
"exploitabilityScore" : 3.9 ,
2024-12-08 03:06:42 +00:00
"impactScore" : 3.6
2023-05-05 20:00:27 +02:00
} ,
2023-04-28 14:00:26 +02:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-28 14:00:26 +02:00
"cvssData" : {
"version" : "3.1" ,
2024-12-08 03:06:42 +00:00
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-04-28 14:00:26 +02:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
2024-12-08 03:06:42 +00:00
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH"
2023-04-28 14:00:26 +02:00
} ,
"exploitabilityScore" : 3.9 ,
2024-12-08 03:06:42 +00:00
"impactScore" : 5.9
2023-04-28 14:00:26 +02:00
}
]
} ,
"weaknesses" : [
2023-05-05 20:00:27 +02:00
{
2024-12-08 03:06:42 +00:00
"source" : "vdisclose@cert-in.org.in" ,
"type" : "Secondary" ,
2023-05-05 20:00:27 +02:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-285"
2023-05-05 20:00:27 +02:00
}
]
} ,
2023-04-28 14:00:26 +02:00
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-04-28 14:00:26 +02:00
"description" : [
{
"lang" : "en" ,
2024-12-08 03:06:42 +00:00
"value" : "CWE-863"
2023-04-28 14:00:26 +02:00
}
]
}
] ,
2023-05-05 20:00:27 +02:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n5008-uc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "BE1B2A5B-60C9-4A59-B55D-AC0094C3B1D6"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n5008-uc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "58261CC1-427F-4A52-A008-6B6716112BBF"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n1008-unc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "AFA4F551-2D31-4702-92D0-CAA5A13F129E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n1008-unc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EFB41652-D278-4292-B7BB-7F070E361DAC"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n1008-uc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "09767926-CFFF-46FE-B4BF-6837B4EA8289"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n1008-uc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BE88C635-0150-480E-8A89-5A56BE05D61E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n1004-uc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "67C8EA84-347F-489B-9D14-F5F0FD70CF3C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n1004-uc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "41AE04A5-3029-4BEB-BDCE-3C0FAF39E31E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n5016-e_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "75.9.0.18-r2" ,
"matchCriteriaId" : "6942BA61-4138-4E0A-8752-7FDE859648BC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n5016-e:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A4DA6501-93EC-41A5-B282-C64C21F60B67"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n5008-e_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "75.9.0.18-r2" ,
"matchCriteriaId" : "252CCDD9-ADDB-409D-9959-0C04EE22476B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n5008-e:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EB8433B3-851C-4B85-98E9-BBC03F9DA4C2"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n7016-uh_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "71.9.0.18-r2" ,
"matchCriteriaId" : "5D7FA22E-4503-4BC8-B44B-95D07C76CE38"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n7016-uh:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F0F41EFC-32FD-4B45-96D0-99704EBBFDF0"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n7032-uh_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "71.9.0.18-r2" ,
"matchCriteriaId" : "6BB803FE-800A-4C0C-B3A2-360CAFF8404E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n7032-uh:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE84B357-0D42-4C10-A33C-E7800423417F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n8064-uh_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "71.9.0.18-r2" ,
"matchCriteriaId" : "0795157C-5761-4B2F-8A0B-D517D1ECFB14"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n8064-uh:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BD889EAE-987D-42C2-9BCE-995583A47894"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n8032-uh_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "71.9.0.18-r2" ,
"matchCriteriaId" : "4EA14E16-90BE-4C8D-A1CD-92A911B74692"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n8032-uh:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "62654248-D2A8-494C-847F-8AF636506F20"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n1004-upc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "57B5543B-1734-4E8F-8836-1AFDA14B1558"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n1004-upc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE9672C3-28C3-4E9B-B30F-86B50EC5BC07"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n1008-upc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "D2D27E22-9CCF-43CB-BBBB-4AFDC7201E1C"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n1008-upc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C9E4CEB9-6C20-4071-9DAF-6D0DAA1FD1A4"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n1008-unpc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "D1F63759-80FE-4A56-8AE3-0F9B99112598"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n1008-unpc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4C8B2388-7F07-4921-A87E-09D3B705A429"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n5008-upc_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "73.9.0.18-r2" ,
"matchCriteriaId" : "9E9E50A7-9795-4619-8C56-C1DB481E7706"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n5008-upc:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5B49E7A8-3823-4BFE-9BC1-86BA575C85AC"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n5016-pe_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "75.9.0.18-r2" ,
"matchCriteriaId" : "2EE2DD36-C16F-4308-80B2-829FEA43CF5D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n5016-pe:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "98BCC15F-0126-436B-AD93-5485B0049051"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n5008-pe_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "75.9.0.18-r2" ,
"matchCriteriaId" : "05601450-3A08-4326-8884-03A93468FBA3"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n5008-pe:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7B3BF03A-B2AD-40E9-8287-0A4BC78358FB"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n7016-uph_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "71.9.0.18-r2" ,
"matchCriteriaId" : "C3A443C3-3520-4B85-AE5C-4230F4BF9067"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n7016-uph:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F4781C7D-E014-4773-8066-2DC6564557DC"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n7032-uph_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "71.9.0.18-r2" ,
"matchCriteriaId" : "3281A9A5-5838-4B16-8205-14FD64FB9E96"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n7032-uph:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A74207F3-9EEE-491D-AFDA-127A107DC40D"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-n7048-uph_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "71.9.0.18-r2" ,
"matchCriteriaId" : "A77B9D2B-A8F5-4B4A-9D02-73F3E41AB0C2"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:milesight:ms-n7048-uph:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1D4B94E3-80EF-4A72-8069-15EAB4644D4C"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-nxxxx-xxg_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "77.9.0.18-r2" ,
"matchCriteriaId" : "1AD1E452-B123-4287-BF44-F6D241F10188"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:milesight:ms-nxxxx-xxt_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "72.9.0.18-r2" ,
"matchCriteriaId" : "450E1C0E-B7D9-4913-B71B-8EBAB904BFA6"
}
]
}
]
}
] ,
2023-04-28 14:00:26 +02:00
"references" : [
{
"url" : "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0121" ,
2023-05-05 20:00:27 +02:00
"source" : "vdisclose@cert-in.org.in" ,
"tags" : [
"Third Party Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2023-0121" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Third Party Advisory"
]
2023-04-28 14:00:26 +02:00
}
]
}