PT-2007-5743 · Acti · Acti Network Video Recorder+1

Shinnai

·

Publicado

2007-08-29

·

Atualizado

2017-09-29

·

CVE-2007-4582

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ACTi Network Video Recorder (NVR) SP2 version 2.0
Description The issue is related to a buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll version 1.1.45.0. This allows remote attackers to execute arbitrary code via a long second argument to the SetText method.
Recommendations For ACTi Network Video Recorder (NVR) SP2 version 2.0, consider disabling the SetText method in the nvUnifiedControl.AUnifiedControl.1 ActiveX control until a patch is available. Restrict access to the nvUnifiedControl.dll to minimize the risk of exploitation.

Exploit

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4582

Produtos afetados

Acti Network Video Recorder
Nvunifiedcontrol.Dll