CRITICAL🇵🇱 Wersja polska

CVE-2024-36388

CVSS 10.0v3.1pub. 2024-06-02upd. 2025-03-04

MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

🤖 AI Analysis
How it works

An attacker can access critical functions of the Milesight DeviceHub platform without possessing any credentials. The lack of authentication mechanisms (CWE-305) and access controls (CWE-306) enables privileged operations to be invoked directly over the network without requiring user interaction. The attack vector is network-based, requires no complex conditions or any privileges.

Impact

An attacker can gain full control over the system, including access to sensitive data, ability to modify it, and disrupt service availability — which corresponds to maximum scores for confidentiality, integrity, and availability on the CVSS scale.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is also recommended to restrict network access to DeviceHub administrative interfaces using a firewall and implement network segmentation until the patch is deployed.

Who is affected

Milesight DeviceHub and Canonical Ubuntu Linux — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Canonical Ubuntu

    OS
    Canonical
    20.04
  • Milesight Devicehub

    APP
    Milesight
    3.0.1-r1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2022-0543CRITICAL10.0⚠ KEVPL ✓same product

Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)

CVE-2020-11651CRITICAL9.8⚠ KEVPL ✓same product

SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE

CVE-2020-7247CRITICAL9.8⚠ KEVPL ✓same product

RCE jako root w OpenSMTPD przez command injection w polu MAIL FROM

CVE-2019-16928CRITICAL9.8⚠ KEVPL ✓same product

RCE w Exim — heap-based buffer overflow w obsłudze komendy EHLO