PT-2016-6636 · Nuuo+1 · Nuuo Nvrmini 2+1
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NUUO NVRmini 2 versions 1.7.6 through 3.0.0
NETGEAR ReadyNAS Surveillance version 1.1.2
Description
The issue is a stack-based buffer overflow in the cgi-bin/cgi main component. It allows remote authenticated users to execute arbitrary code via the
sn parameter to the "transfer license" command.Recommendations
For NUUO NVRmini 2 versions 1.7.6 through 3.0.0, update to a version that fixes this issue.
For NETGEAR ReadyNAS Surveillance version 1.1.2, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the
transfer license command until a patch is available.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nuuo Nvrmini 2
Readynas Surveillance