Vulnerability Details CVE-2023-30466
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device.
Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-30466
-
cpe:2.3:h:milesight:ms-n1004-uc:-
-
cpe:2.3:h:milesight:ms-n1004-upc:-
-
cpe:2.3:h:milesight:ms-n1008-uc:-
-
cpe:2.3:h:milesight:ms-n1008-unc:-
-
cpe:2.3:h:milesight:ms-n1008-unpc:-
-
cpe:2.3:h:milesight:ms-n1008-upc:-
-
cpe:2.3:h:milesight:ms-n5008-e:-
-
cpe:2.3:h:milesight:ms-n5008-pe:-
-
cpe:2.3:h:milesight:ms-n5008-uc:-
-
cpe:2.3:h:milesight:ms-n5008-upc:-
-
cpe:2.3:h:milesight:ms-n5016-e:-
-
cpe:2.3:h:milesight:ms-n5016-pe:-
-
cpe:2.3:h:milesight:ms-n7016-uh:-
-
cpe:2.3:h:milesight:ms-n7016-uph:-
-
cpe:2.3:h:milesight:ms-n7032-uh:-
-
cpe:2.3:h:milesight:ms-n7032-uph:-
-
cpe:2.3:h:milesight:ms-n7048-uph:-
-
cpe:2.3:h:milesight:ms-n8032-uh:-
-
cpe:2.3:h:milesight:ms-n8064-uh:-
-
cpe:2.3:o:milesight:ms-n1004-uc_firmware:-
-
cpe:2.3:o:milesight:ms-n1004-upc_firmware:-
-
cpe:2.3:o:milesight:ms-n1008-uc_firmware:-
-
cpe:2.3:o:milesight:ms-n1008-unc_firmware:-
-
cpe:2.3:o:milesight:ms-n1008-unpc_firmware:-
-
cpe:2.3:o:milesight:ms-n1008-upc_firmware:-
-
cpe:2.3:o:milesight:ms-n5008-e_firmware:-
-
cpe:2.3:o:milesight:ms-n5008-pe_firmware:-
-
cpe:2.3:o:milesight:ms-n5008-uc_firmware:-
-
cpe:2.3:o:milesight:ms-n5008-upc_firmware:-
-
cpe:2.3:o:milesight:ms-n5016-e_firmware:-
-
cpe:2.3:o:milesight:ms-n5016-pe_firmware:-
-
cpe:2.3:o:milesight:ms-n7016-uh_firmware:-
-
cpe:2.3:o:milesight:ms-n7016-uph_firmware:-
-
cpe:2.3:o:milesight:ms-n7032-uh_firmware:-
-
cpe:2.3:o:milesight:ms-n7032-uph_firmware:-
-
cpe:2.3:o:milesight:ms-n7048-uph_firmware:-
-
cpe:2.3:o:milesight:ms-n8032-uh_firmware:-
-
cpe:2.3:o:milesight:ms-n8064-uh_firmware:-
-
cpe:2.3:o:milesight:ms-nxxxx-xxg_firmware:*
-
cpe:2.3:o:milesight:ms-nxxxx-xxt_firmware:*