Vulnerability Description
The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Panasonic | Network Camera Recorder Firmware | < 4.04r03 |
| Panasonic | Network Camera Recorder | - |
References
- http://panasonic.net/pcc/cgi-bin/products/netwkcam/download_us/tbookmarka_m.cgi?Broken LinkPatch
- http://www.zerodayinitiative.com/advisories/ZDI-14-363/Third Party AdvisoryVDB Entry
- http://panasonic.net/pcc/cgi-bin/products/netwkcam/download_us/tbookmarka_m.cgi?Broken LinkPatch
- http://www.zerodayinitiative.com/advisories/ZDI-14-363/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2014-8756?
CVE-2014-8756 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an...
How severe is CVE-2014-8756?
CVE-2014-8756 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8756?
Check the references section above for vendor advisories and patch information. Affected products include: Panasonic Network Camera Recorder Firmware, Panasonic Network Camera Recorder.