CERT-In Vulnerability Note
CIVN-2022-0352
Denial of Service Vulnerability in Milesight Video Management Systems (VMS)
Original Issue Date:September 14, 2022
Severity Rating: HIGH
Software Affected
- Milesight Video Management Systems (VMS) - all firmware versions prior to 40.7.0.79-r1
Overview
A vulnerability has been reported in Milesight Video Management Systems (VMS), which could allow a remote attacker to cause a Denial of Service condition on the targeted network camera.
Description
This vulnerability exists in Milesight Video Management Systems (VMS), due to improper input handling at camera¿s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera.
Successful exploitation of this vulnerability could allow the attacker to cause a Denial of Service condition on the targeted device.
Credit
This vulnerability is reported by Souvik Kandar and Arko Dhar from Redinent Innovations Engineering & Research Team, Karnataka, India.
Solution
Update Milesight VMS firmware to latest version
https://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view?usp=sharing
Vendor Information
Milesight
https://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view?usp=sharing
References
Milesight
https://drive.google.com/file/d/1D4I8M_R31CRaA8mZjFnWNgGjnQjtITzB/view?usp=sharing
CVE Name
CVE-2022-3001
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|