CVE-2015-2098
CVE-2015-2098
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4) AudioOnlySiteChannel function in the WESPPlayback.WESPPlaybackCtrl.1 control; (5) Connect or (6) ConnectEx function in the WESPPTZ.WESPPTZCtrl.1 control; (7) SiteChannel property in the WESPPlayback.WESPPlaybackCtrl.1 control; (8) SiteName property in the WESPPlayback.WESPPlaybackCtrl.1 control; or (9) OpenDVrSSite function in the WESPPTZ.WESPPTZCtrl.1 control.
Productos afectados
n/a · n/aPoCs públicas encontradas — 3
exploitdbwww.exploit-db.com/exploits/36603no verificadoexploitdbwww.exploit-db.com/exploits/36606no verificadoexploitdbwww.exploit-db.com/exploits/36519no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://www.zerodayinitiative.com/advisories/ZDI-15-058/http://www.zerodayinitiative.com/advisories/ZDI-15-060/http://www.zerodayinitiative.com/advisories/ZDI-15-061/http://www.zerodayinitiative.com/advisories/ZDI-15-064/http://www.zerodayinitiative.com/advisories/ZDI-15-065/http://www.zerodayinitiative.com/advisories/ZDI-15-066/