CVE-2014-8756
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/10/2014
Last modified:
12/04/2025
Description
The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:panasonic:network_camera_recorder_firmware:*:*:*:*:*:*:*:* | 4.04r03 (excluding) | |
cpe:2.3:h:panasonic:network_camera_recorder:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://panasonic.net/pcc/cgi-bin/products/netwkcam/download_us/tbookmarka_m.cgi?m=%20&mm=2010073014092324
- http://www.zerodayinitiative.com/advisories/ZDI-14-363/
- http://panasonic.net/pcc/cgi-bin/products/netwkcam/download_us/tbookmarka_m.cgi?m=%20&mm=2010073014092324
- http://www.zerodayinitiative.com/advisories/ZDI-14-363/