CVE-2023-43261
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
7.5
CVSS
59.6%
EPSS (exploit prob.)
99th
EPSS percentile
2023-10-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-532
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| milesight | ur5x_firmware | < 35.3.0.7 |
| milesight | ur51 | all versions |
| milesight | ur52 | all versions |
| milesight | ur55 | all versions |
| milesight | ur32l_firmware | < 35.3.0.7 |
| milesight | ur32l | all versions |
| milesight | ur32_firmware | < 35.3.0.7 |
| milesight | ur32 | all versions |
| milesight | ur35_firmware | < 35.3.0.7 |
| milesight | ur35 | all versions |
| milesight | ur41_firmware | < 35.3.0.7 |
| milesight | ur41 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html
- https://github.com/win3zz/CVE-2023-43261
- https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
- https://support.milesight-iot.com/support/home
- http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html
- https://github.com/win3zz/CVE-2023-43261
- https://medium.com/%40win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
- https://support.milesight-iot.com/support/home
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-43261