Vulnerability Description
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Acti | Nvr | 2.3.04.07 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/158771/ACTi-NVR3-Standard-Professional-ServExploitThird Party Advisory
- https://github.com/megamagnus/cve-2020-15956ExploitThird Party Advisory
- https://www2.acti.com/nvr3ProductVendor Advisory
- http://packetstormsecurity.com/files/158771/ACTi-NVR3-Standard-Professional-ServExploitThird Party Advisory
- https://github.com/megamagnus/cve-2020-15956ExploitThird Party Advisory
- https://www2.acti.com/nvr3ProductVendor Advisory
FAQ
What is CVE-2020-15956?
CVE-2020-15956 is a vulnerability with a CVSS score of 7.5 (HIGH). ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.
How severe is CVE-2020-15956?
CVE-2020-15956 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15956?
Check the references section above for vendor advisories and patch information. Affected products include: Acti Nvr.