vendor:
Industrial Routers
by:
Bipin Jitiya
6.1
CVSS
HIGH
Information Disclosure and Weak Encryption
200
CWE
Product Name: Industrial Routers
Affected Version From: UR5X, UR32L, UR32, UR35, UR41 and potentially other Industrial Cellular Routers
Affected Version To: UR5X, UR32L, UR32, UR35, UR41 and potentially other Industrial Cellular Routers
Patch Exists: NO
Related CWE: CVE-2023-43261
CPE: a:milesight-iot:ur5x, cpe:/a:milesight-iot:ur32l, cpe:/a:milesight-iot:ur32, cpe:/a:milesight-iot:ur35, cpe:/a:milesight-iot:ur41
Platforms Tested: Ubuntu 20.04.6 LTS with Python 3.8.10
2023
Credential Leakage Through Unprotected System Logs and Weak Password Encryption
The vulnerability allows an attacker to access sensitive credentials due to unprotected system logs and weak password encryption implemented in Milesight IoT industrial routers. By exploiting this flaw, an adversary could decrypt and extract passwords leading to unauthorized access. This vulnerability has been assigned CVE-2023-43261.
Mitigation:
To mitigate this vulnerability, it is recommended to ensure that system logs are properly protected and use strong encryption methods for storing passwords. Regular security audits should be conducted to identify and address such issues.