7.5
CVSSv2

CVE-2015-2097

Published: 09/03/2015 Updated: 30/11/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote malicious users to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control.

Vulnerable Product Search on Vulmon Subscribe to Product

webgate webgate embedded standard protocol sdk -

Exploits

<html> <!-- # Exploit Title: WebGate eDVR Manager WESPMonitorWESPMonitorCtrl LoadImage Stack Buffer Overflow Remote Code Execution (0 day) # Date: 26th MArch, 2015 # Exploit Author: Praveen Darshanam # Vendor Homepage: wwwwebgateinccom/wgi/eng/ # Software Link: wwwwebgateinccom/wgi_htdocs/eng/dcenter/viewphp?id=wgi_eng& ...
<html> <!-- # Exploit Title: WebGate eDVR Manager Connect Method Stack Buffer Overflow # Date: 01st April, 2015 # Exploit Author: Praveen Darshanam # Vendor Homepage: wwwwebgateinccom/wgi/eng/ # Software Link: wwwwebgateinccom/wgi_htdocs/eng/dcenter/viewphp?id=wgi_eng&page=1&sn1=&divpage=1&sn=off&ss=o ...
<html> <!-- # Exploit Title: WESP SDK ChangePassword Stack Overflow # Date: 01st April, 2015 # Exploit Author: Praveen Darshanam # Vendor Homepage: wwwwebgateinccom/wgi/eng/ # Software Link: wwwwebgateinccom/wgi_htdocs/eng/bbs/zboardphp?id=sdk_pds_eng # Version: WESP SDK (package version 12) # Tested on: Windows XP SP3 ...