Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vectors to the (1) GetRecFileInfo function in the FileConverter.FileConverterCtrl.1 control, (2) Login function in the LoginContoller.LoginControllerCtrl.1 control, or (3) GetThumbnail function in the WESPPlayback.WESPPlaybackCtrl.1 control.
References
Link | Resource |
---|---|
http://www.zerodayinitiative.com/advisories/ZDI-15-055/ | Third Party Advisory VDB Entry |
http://www.zerodayinitiative.com/advisories/ZDI-15-056/ | Third Party Advisory VDB Entry |
http://www.zerodayinitiative.com/advisories/ZDI-15-063/ | Third Party Advisory VDB Entry |
Configurations
History
03 Aug 2021, 19:55
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-055/ - Third Party Advisory, VDB Entry | |
References | (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-063/ - Third Party Advisory, VDB Entry | |
References | (MISC) http://www.zerodayinitiative.com/advisories/ZDI-15-056/ - Third Party Advisory, VDB Entry | |
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.8 |
CWE | CWE-120 | |
CPE | cpe:2.3:a:webgateinc:control_center:-:*:*:*:*:*:*:* |
22 Jul 2021, 18:43
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-07-22 18:15
Updated : 2024-02-04 21:47
NVD link : CVE-2015-2099
Mitre link : CVE-2015-2099
CVE.ORG link : CVE-2015-2099
JSON object : View
Products Affected
webgateinc
- control_center
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')