Lucene search

K
cveCERT-InCVE-2022-3001
HistorySep 15, 2022 - 3:15 p.m.

CVE-2022-3001

2022-09-1515:15:10
CWE-20
CERT-In
web.nvd.nist.gov
30
7
cve-2022-3001
milesight video management systems
vms
firmware
vulnerability
dos
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.8%

This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera. Successful exploitation of this vulnerability could allow the attacker to cause a Denial of Service condition on the targeted device.

Affected configurations

Nvd
Node
milesightvideo_management_systemsMatch-enterprise
AND
milesightvideo_management_systems_firmwareRange<40.7.0.79
OR
milesightvideo_management_systems_firmwareMatch40.7.0.79-
VendorProductVersionCPE
milesightvideo_management_systems-cpe:2.3:h:milesight:video_management_systems:-:*:*:*:enterprise:*:*:*
milesightvideo_management_systems_firmware*cpe:2.3:o:milesight:video_management_systems_firmware:*:*:*:*:*:*:*:*
milesightvideo_management_systems_firmware40.7.0.79cpe:2.3:o:milesight:video_management_systems_firmware:40.7.0.79:-:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Video Management Systems",
    "vendor": "Milesight",
    "versions": [
      {
        "lessThan": "40.7.0.79-r1",
        "status": "affected",
        "version": "VMS",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

41.8%

Related for CVE-2022-3001