9.3
CVSSv2

CVE-2010-4230

Published: 17/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote malicious users to execute arbitrary code via a long string in the first argument to the connect method.

Vulnerable Product Search on Vulmon Subscribe to Product

camtron cmnc-200_firmware 1.102a-008

camtron cmnc-200

tecvoz cmnc-200_firmware 1.102a-008

tecvoz cmnc-200

Exploits

Finding 1: Buffer Overflow in ActiveX Control CVE: CVE-2010-4230 The CMNC-200 IP Camera ActiveX control identified by CLSID {DD01C8CA-5DA0-4B01-9603-B7194E561D32} is vulnerable to a stack overflow on the first argument of the connect method The vulnerability can be used to set the EIP register, allowing a reliable exploitation The example code ...
The Camtron CMNC-200 IP Camera suffers from buffer overflow, administrative bypass, default account and directory traversal vulnerabilities ...