CVE-2015-2097
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 24%
from disclosure to weapon17 days
Published on NVDMar 9
1st PoC+17d
exploitation probability
24%top 2% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control.
Affected products
n/a · n/apublic PoCs found — 7
cve_referencepacketstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.htmlunverifiedcve_referencewww.exploit-db.com/exploits/36505/unverifiedcve_referencewww.exploit-db.com/exploits/36602/unverifiedcve_referencewww.exploit-db.com/exploits/36607/unverifiedexploitdbwww.exploit-db.com/exploits/36505unverifiedexploitdbwww.exploit-db.com/exploits/36607unverifiedexploitdbwww.exploit-db.com/exploits/36602unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.htmlhttp://seclists.org/fulldisclosure/2015/Feb/90https://www.exploit-db.com/exploits/36505/https://www.exploit-db.com/exploits/36602/https://www.exploit-db.com/exploits/36607/http://www.osvdb.org/118893http://www.osvdb.org/118896http://www.osvdb.org/118902http://www.securityfocus.com/bid/72835http://www.zerodayinitiative.com/advisories/ZDI-15-059/http://www.zerodayinitiative.com/advisories/ZDI-15-062/http://www.zerodayinitiative.com/advisories/ZDI-15-068/