Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-24595
HistoryJul 06, 2023 - 3:15 p.m.

Command injection

2023-07-0615:15:00
PRIOn knowledge base
www.prio-n.com
7
os command injection
ys_thirdparty system_user_script
milesight ur32l v32.3.0.5
network requests
vulnerability
unauthorized command execution
attacker
sequence of requests

0.001 Low

EPSS

Percentile

36.7%

An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CPENameOperatorVersion
ur32l_firmwareeq32.3.0.5

0.001 Low

EPSS

Percentile

36.7%

Related for PRION:CVE-2023-24595