vendor:
MXP
by:
otokoyama
8,8
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: MXP
Affected Version From: F7.0
Affected Version To: F7.0
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
TANDBERG BoF v0.1 – Tandberg MXP F7.0 Buffer Overflow Vulnerability PoC
The vulnerability is caused by the system passing all usernames and passwords to a log file, which can be exploited by sending a 251 char string of /x20 commonly known as a blank space. The vendor has fixed this vulnerability in later releases of its firmware.
Mitigation:
Upgrade to the latest version of the firmware to fix the vulnerability.