Vulnerability Description
iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary code. Attackers can input a crafted payload exceeding 260 bytes through the System Setup interface to overwrite SEH records and execute shellcode with application privileges.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://securimport.com/university/videovigilancia-ip/software/493-software-isma
- https://www.exploit-db.com/exploits/45349
- https://www.vulncheck.com/advisories/ismartviewpro-buffer-overflow-via-savepath-
FAQ
What is CVE-2018-25283?
CVE-2018-25283 is a vulnerability with a CVSS score of 8.4 (HIGH). iSmartViewPro 1.5 contains a structured exception handling (SEH) buffer overflow vulnerability in the 'Save Path for Snapshot and Record file' field that allows local attackers to execute arbitrary co...
How severe is CVE-2018-25283?
CVE-2018-25283 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25283?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.