SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-43261

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

HIGH 7.5EPSS 59.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 59.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
59.61% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-532
Affected
milesight/ur5x firmware · milesight/ur32l firmware · milesight/ur32 firmware · milesight/ur35 firmware · milesight/ur41 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.