CRITICAL🇵🇱 Wersja polska

CVE-2024-36389

CVSS 9.8v3.1pub. 2024-06-02upd. 2025-04-10

MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass

🤖 AI Analysis
How it works

The system generates values used in the authentication process (e.g., session tokens, nonces, or identifiers) in an insufficiently random or predictable manner. An attacker can predict or reproduce these values without knowledge of the correct authentication credentials. This allows access to the system while bypassing the standard login process.

Impact

An unauthenticated attacker can remotely gain full access to the system over the network — affecting confidentiality, integrity, and availability of data and device functions.

Mitigation & patch

Apply patches available from the manufacturer according to the references provided. It is also recommended to restrict network access to the DeviceHub interface exclusively to trusted networks or VPN until the patch is deployed.

Who is affected

Milesight DeviceHub — versions specified in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Canonical Ubuntu

    OS
    Canonical
    20.04
  • Milesight Devicehub

    APP
    Milesight
    3.0.1-r1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2022-0543CRITICAL10.0⚠ KEVPL ✓same product

Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)

CVE-2020-11651CRITICAL9.8⚠ KEVPL ✓same product

SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE

CVE-2020-7247CRITICAL9.8⚠ KEVPL ✓same product

RCE jako root w OpenSMTPD przez command injection w polu MAIL FROM

CVE-2019-16928CRITICAL9.8⚠ KEVPL ✓same product

RCE w Exim — heap-based buffer overflow w obsłudze komendy EHLO