CVE-2015-2097
Summary
| CVE | CVE-2015-2097 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-09 14:59:15 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Webgate | Webgate Embedded Standard Protocol Sdk | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WebGate eDVR Manager Stack Buffer Overflow ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| WebGate eDVR Manager CVE-2015-2097 Multiple Stack Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| WebGate eDVR Manager Stack Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| www.osvdb.org/118893 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Full Disclosure: WESP SDK multiple Remote Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| Webgate WESP SDK 1.2 ChangePassword Stack Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| www.osvdb.org/118896 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| WebGate eDVR Manager 2.6.4 Connect Method Stack Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| www.osvdb.org/118902 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.