CVE Published: 15/09/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: CERT-In |
Vendor: Milesight |
Product: Video Management Systems Status : PUBLISHED
CVE-2022-3001 Description
This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera. Successful exploitation of this vulnerability could allow the attacker to cause a Denial of Service condition on the targeted device.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H