Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allows remote attackers to execute arbitrary code via a long second argument to the SetText method.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PActi Network Video Recorder
APPActisp2_2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
Related vulnerabilities
CVE-2007-4583MEDIUM5.0same product
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1...
CVE-2017-3184CRITICAL9.8PL ✓same vendor
ACTi Camera Firmware — nieautoryzowany dostęp do strony factory reset
CVE-2017-3185CRITICAL9.8PL ✓same vendor
ACTi Camera Firmware — dane uwierzytelniające w żądaniach GET
CVE-2017-3186CRITICAL9.8PL ✓same vendor
ACTi Camera Firmware — nielosowe domyślne dane uwierzytelniające
CVE-2020-15956HIGH7.5same vendor
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigge...