PT-2015-6650 · Panasonic · Panasonic Security Api (Ps-Api) Activex Sdk

Ariele Caltabiano

+1

·

Published

2015-06-24

·

Updated

2016-12-07

·

CVE-2015-4647

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Panasonic Security API (PS-API) ActiveX SDK versions prior to 8.10.18
Description The issue concerns stack-based buffer overflows in the Ipropsapi component of the Panasonic Security API (PS-API) ActiveX SDK. This can be exploited by remote attackers to execute arbitrary code via a long string in the FilePassword property or to the GetStringInfo method.
Recommendations For versions prior to 8.10.18, update to version 8.10.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the FilePassword property and the GetStringInfo method until a patch is applied. Avoid using long strings in these components to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-4647
ZDI-15-259
ZDI-15-260

Affected Products

Panasonic Security Api (Ps-Api) Activex Sdk