vendor:
CMNC-200 IP Camera ActiveX control
by:
N/A
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CMNC-200 IP Camera ActiveX control
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: CVE-2010-4230
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Buffer Overflow in ActiveX Control
The CMNC-200 IP Camera ActiveX control identified by CLSID {DD01C8CA-5DA0-4B01-9603-B7194E561D32} is vulnerable to a stack overflow on the first argument of the connect method. The vulnerability can be used to set the EIP register, allowing a reliable exploitation. The example code below triggers the vulnerability.
Mitigation:
To limit exposure, network access to these devices should be limited to authorized personnel through the use of Access Control Lists and proper network segmentation.