PT-2007-5743 · Acti · Acti Network Video Recorder+1

Shinnai

·

Published

2007-08-29

·

Updated

2017-09-29

·

CVE-2007-4582

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ACTi Network Video Recorder (NVR) SP2 version 2.0
Description The issue is related to a buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll version 1.1.45.0. This allows remote attackers to execute arbitrary code via a long second argument to the SetText method.
Recommendations For ACTi Network Video Recorder (NVR) SP2 version 2.0, consider disabling the SetText method in the nvUnifiedControl.AUnifiedControl.1 ActiveX control until a patch is available. Restrict access to the nvUnifiedControl.dll to minimize the risk of exploitation.

Exploit

Fix

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4582

Affected Products

Acti Network Video Recorder
Nvunifiedcontrol.Dll