Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-25095
HistoryJul 06, 2023 - 3:15 p.m.

Buffer overflow

2023-07-0615:15:00
PRIOn knowledge base
www.prio-n.com
7
buffer overflow
vtysh_ubus
milesight ur32l
sprintf pattern
http request
arbitrary code execution
set_qos function

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.7%

Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_qos function with the rule_name variable with two possible format strings that represent negated commands.

CPENameOperatorVersion
ur32l_firmwareeq32.3.0.5

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.7%

Related for PRION:CVE-2023-25095