PT-2016-6636 · Nuuo+1 · Nuuo Nvrmini 2+1
Pedro Ribeiro
·
Publicado
2016-08-31
·
Atualizado
2017-09-03
·
CVE-2016-5680
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NUUO NVRmini 2 versions 1.7.6 through 3.0.0
NETGEAR ReadyNAS Surveillance version 1.1.2
Description
The issue is a stack-based buffer overflow in the cgi-bin/cgi main component. It allows remote authenticated users to execute arbitrary code via the
sn parameter to the "transfer license" command.Recommendations
For NUUO NVRmini 2 versions 1.7.6 through 3.0.0, update to a version that fixes this issue.
For NETGEAR ReadyNAS Surveillance version 1.1.2, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the
transfer license command until a patch is available.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nuuo Nvrmini 2
Readynas Surveillance