Vulnerabilities > Acti
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-08-04 | CVE-2020-15956 | Classic Buffer Overflow vulnerability in Acti NVR 2.3.04.07/3.0.12.42 ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload. | 5.0 |
2017-12-16 | CVE-2017-3186 | Use of Hard-coded Credentials vulnerability in Acti Camera Firmware A1D500V6.11.31Ac ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. | 10.0 |
2017-12-16 | CVE-2017-3185 | Information Exposure vulnerability in Acti Camera Firmware A1D500V6.11.31Ac ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources. | 5.0 |
2017-12-16 | CVE-2017-3184 | Use of Hard-coded Credentials vulnerability in Acti Camera Firmware A1D500V6.11.31Ac ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. | 10.0 |
2007-08-29 | CVE-2007-4583 | Path Traversal vulnerability in Acti Network Video Recorder Sp22.0 Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method. | 5.0 |
2007-08-29 | CVE-2007-4582 | Buffer Errors vulnerability in Acti Network Video Recorder Sp22.0 Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allows remote attackers to execute arbitrary code via a long second argument to the SetText method. | 7.5 |