vendor:
EDGE series
by:
Anonymous
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: EDGE series
Affected Version From: EDGE series
Affected Version To: EDGE series
Patch Exists: YES
Related CWE: CVE-2014-5123
CPE: h:lorex_technology:edge_series
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3, Windows 7 x64
2014
Buffer Overflow Vulnerability in Lorex Technologies EDGE Series
A buffer overflow vulnerability in the ActiveX control INetViewX bundled by Lorex Technologies in their EDGE series of video surveillance systems allows remote code execution. The vulnerability can be triggered by a long string (10000+ characters) in the HTTP_PORT parameter. The instruction pointer can be very easily controlled in XP by the characters 109 to 113 in the string.
Mitigation:
Lorex Technologies has released a patch for this vulnerability.