CVE-2015-2099

Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the LoginContoller.LoginControllerCtrl.1 control, or (3) GetThumbnail function in the WESPPlayback.WESPPlaybackCtrl.1 control.
References
Link Resource
http://www.zerodayinitiative.com/advisories/ZDI-15-055/ Third Party Advisory VDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-15-056/ Third Party Advisory VDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-15-063/ Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:webgateinc:control_center:-:*:*:*:*:*:*:*

History

03 Aug 2021, 19:55

Type Values Removed Values Added
References (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-055/ - (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-055/ - Third Party Advisory, VDB Entry
References (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-063/ - (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-063/ - Third Party Advisory, VDB Entry
References (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-056/ - (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-056/ - Third Party Advisory, VDB Entry
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 8.8
CWE CWE-120
CPE cpe:2.3:a:webgateinc:control_center:-:*:*:*:*:*:*:*

22 Jul 2021, 18:43

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-22 18:15

Updated : 2024-02-04 21:47


NVD link : CVE-2015-2099

Mitre link : CVE-2015-2099

CVE.ORG link : CVE-2015-2099


JSON object : View

Products Affected

webgateinc

  • control_center
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')