PT-2023-18721 · Milesight · Milesight Vpn

·

CVE-2023-22844

·

Publicado

2023-07-06

·

Atualizado

2023-07-13

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Milesight VPN version 2.0.2
Description An authentication bypass issue exists in the requestHandlers.js verifyToken functionality. A specially-crafted network request can lead to authentication bypass, allowing an attacker to send a network request and trigger this issue.
Recommendations For Milesight VPN version 2.0.2, consider disabling the verifyToken functionality in requestHandlers.js as a temporary workaround until a patch is available. Restrict access to the verifyToken function to minimize the risk of exploitation. Avoid using the verifyToken functionality in the affected API endpoint until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22844

Produtos afetados

Milesight Vpn