CVE-2014-1201

UnknownEPSS 29.46%

Last modified

CVE-2014-1201 is a vulnerability of currently unknown severity. Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.. EPSS estimates a 29.46% chance of exploitation in the next 30 days.

Description

Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.

Metrics

EPSS Probability
29.46%

97.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Lorex TechnologyEdge Lh310 Firmware7-35-28-1b26e
LorextechnologyEdgelh310
Lorex TechnologyEdge3 Lh340 Firmware11.19.85_1fe3a
LorextechnologyEdge3lh340
Lorex TechnologyEdge2 Lh330 Firmware11.17.38-33_1d97a
LorextechnologyEdge2lh330
Lorex TechnologyEdge\+ Lh320 Firmware7-35-28-1b26e
LorextechnologyEdge\+lh320

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-1201?
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.
How severe is CVE-2014-1201?
Severity scoring for CVE-2014-1201 is pending analysis. The EPSS model estimates a 29.46% probability of exploitation in the next 30 days.
How do I fix CVE-2014-1201?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-1201?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST