PT-2007-5743 · Acti · Acti Network Video Recorder+1
Shinnai
·
Published
2007-08-29
·
Updated
2017-09-29
·
CVE-2007-4582
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ACTi Network Video Recorder (NVR) SP2 version 2.0
Description
The issue is related to a buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll version 1.1.45.0. This allows remote attackers to execute arbitrary code via a long second argument to the
SetText method.Recommendations
For ACTi Network Video Recorder (NVR) SP2 version 2.0, consider disabling the
SetText method in the nvUnifiedControl.AUnifiedControl.1 ActiveX control until a patch is available. Restrict access to the nvUnifiedControl.dll to minimize the risk of exploitation.Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acti Network Video Recorder
Nvunifiedcontrol.Dll