MileSight DeviceHub Denial of Service Vulnerability
CVE-2024-36390

7.5HIGH

Key Information:

Vendor

Milesight

Status
Vendor
CVE Published:
2 June 2024

What is CVE-2024-36390?

MileSight DeviceHub is impacted by a vulnerability that stems from improper input validation, categorized under CWE-20. This flaw could be exploited by malicious actors to orchestrate a denial of service, affecting the availability of the DeviceHub for users. Organizations using this product should take precautions to mitigate potential exploitation of this vulnerability and ensure robust security practices are in place.

Affected Version(s)

DeviceHub v3.0.1-r1 for Ubuntu 20.04

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claroty Research – Team 82
.