Milesight / MilesightVPN
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-22844 | An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request… | CRITICAL | 9.8 | Jul 6, 2023 |
| CVE-2023-22319 | A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to… | CRITICAL | 9.8 | Jul 6, 2023 |
| CVE-2023-23907 | A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to arbitr… | HIGH | 7.5 | Jul 6, 2023 |
| CVE-2023-22371 | An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network request c… | HIGH | 8.1 | Jul 6, 2023 |
| CVE-2023-24497 | Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP reques… | MEDIUM | 4.7 | Jul 6, 2023 |
| CVE-2023-24496 | Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP reques… | MEDIUM | 4.7 | Jul 6, 2023 |
Showing 1 to 6 of 6 CVEs