| CERT-In Vulnerability Note 
                                                                      CIVN-2022-0352 Denial of Service Vulnerability in Milesight Video Management Systems (VMS)
 Original Issue Date:September 14, 2022
 Severity Rating: HIGH
 Software Affected  Milesight Video Management Systems (VMS) - all firmware versions prior to 40.7.0.79-r1
 Overview A vulnerability has been reported in Milesight Video Management Systems (VMS), which could allow a remote attacker to cause a Denial of Service condition on the targeted network camera. DescriptionThis vulnerability exists in Milesight Video Management Systems (VMS), due to improper input handling at camera¿s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera. 
 Successful exploitation of this vulnerability could allow the attacker to cause a Denial of Service condition on the targeted device.
 
 Credit
 
 This vulnerability is reported by Souvik Kandar and Arko Dhar from Redinent Innovations Engineering & Research Team, Karnataka, India.
 
 
 SolutionUpdate Milesight VMS firmware to latest version https://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view?usp=sharing
 
 Vendor Information Milesighthttps://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view?usp=sharing
 
 References Milesighthttps://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view?usp=sharing
 
 CVE NameDisclaimerCVE-2022-3001
 
 The information provided herein is on "as is" basis, without warranty of any kind.  Contact Information  Email: info@cert-in.org.in  Phone: +91-11-24368572 Postal address  Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology
 Government of India
 Electronics Niketan
 6, CGO Complex, Lodhi Road,
 New Delhi - 110 003
 India
   |