Vulnerabilities > CVE-2007-2239 - Remote Buffer Overflow vulnerability in Axis Camera Control ActiveX Control AxisCamControl.OCX

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
axis
critical
nessus

Summary

Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long argument.

Vulnerable Configurations

Part Description Count
Hardware
Axis
70

Nessus

NASL familyWindows
NASL idAXIS_CAMIMAGE_SAVEBMP_OVERFLOW.NASL
descriptionThe remote host contains a version of the
last seen2020-06-01
modified2020-06-02
plugin id25161
published2007-05-08
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/25161
titleAXIS Camera Control (aka CamImage) AxisCamControl.ocx ActiveX SaveBMP Method Overflow