{"api_version":"1","generated_at":"2026-07-23T07:37:03+00:00","cve":"CVE-2015-2097","urls":{"html":"https://cve.report/CVE-2015-2097","api":"https://cve.report/api/cve/CVE-2015-2097.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-2097","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-2097"},"summary":{"title":"CVE-2015-2097","description":"Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-03-09 14:59:15","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://packetstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.html","name":"http://packetstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"WebGate eDVR Manager Stack Buffer Overflow ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/72835","name":"http://www.securityfocus.com/bid/72835","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WebGate eDVR Manager CVE-2015-2097 Multiple Stack Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-059/","name":"http://www.zerodayinitiative.com/advisories/ZDI-15-059/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/36505/","name":"https://www.exploit-db.com/exploits/36505/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WebGate eDVR Manager Stack Buffer Overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-062/","name":"http://www.zerodayinitiative.com/advisories/ZDI-15-062/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/118893","name":"http://www.osvdb.org/118893","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://seclists.org/fulldisclosure/2015/Feb/90","name":"http://seclists.org/fulldisclosure/2015/Feb/90","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Full Disclosure: WESP SDK multiple Remote Code Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/36602/","name":"https://www.exploit-db.com/exploits/36602/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Webgate WESP SDK 1.2 ChangePassword Stack Overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/118896","name":"http://www.osvdb.org/118896","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/36607/","name":"https://www.exploit-db.com/exploits/36607/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"WebGate eDVR Manager 2.6.4 Connect Method Stack Buffer Overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/118902","name":"http://www.osvdb.org/118902","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-068/","name":"http://www.zerodayinitiative.com/advisories/ZDI-15-068/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-2097","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2097","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"2097","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"webgate","cpe5":"webgate_embedded_standard_protocol_sdk","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:02:43.393Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"118902","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/118902"},{"name":"118893","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/118893"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-059/"},{"name":"36607","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/36607/"},{"name":"36505","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/36505/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.html"},{"name":"72835","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/72835"},{"name":"36602","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/36602/"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-068/"},{"name":"118896","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/118896"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-062/"},{"name":"20150223 WESP SDK multiple Remote Code Execution Vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://seclists.org/fulldisclosure/2015/Feb/90"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-02-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-11-28T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"118902","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/118902"},{"name":"118893","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/118893"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-059/"},{"name":"36607","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/36607/"},{"name":"36505","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/36505/"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.html"},{"name":"72835","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/72835"},{"name":"36602","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/36602/"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-068/"},{"name":"118896","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/118896"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-15-062/"},{"name":"20150223 WESP SDK multiple Remote Code Execution Vulnerabilities","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://seclists.org/fulldisclosure/2015/Feb/90"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-2097","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"118902","refsource":"OSVDB","url":"http://www.osvdb.org/118902"},{"name":"118893","refsource":"OSVDB","url":"http://www.osvdb.org/118893"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-15-059/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-059/"},{"name":"36607","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/36607/"},{"name":"36505","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/36505/"},{"name":"http://packetstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/131072/WebGate-eDVR-Manager-Stack-Buffer-Overflow.html"},{"name":"72835","refsource":"BID","url":"http://www.securityfocus.com/bid/72835"},{"name":"36602","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/36602/"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-15-068/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-068/"},{"name":"118896","refsource":"OSVDB","url":"http://www.osvdb.org/118896"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-15-062/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-15-062/"},{"name":"20150223 WESP SDK multiple Remote Code Execution Vulnerabilities","refsource":"FULLDISC","url":"http://seclists.org/fulldisclosure/2015/Feb/90"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-2097","datePublished":"2015-03-09T14:00:00.000Z","dateReserved":"2015-02-26T00:00:00.000Z","dateUpdated":"2024-08-06T05:02:43.393Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-03-09 14:59:15","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:webgate:webgate_embedded_standard_protocol_sdk:-:*:*:*:*:*:*:*","matchCriteriaId":"7184E0B9-F721-4850-8301-E63E157034FB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"2097","Ordinal":"1","Title":"CVE-2015-2097","CVE":"CVE-2015-2097","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"2097","Ordinal":"1","NoteData":"Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control.","Type":"Description","Title":"CVE-2015-2097"},{"CveYear":"2015","CveId":"2097","Ordinal":"2","NoteData":"2015-03-09","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"2097","Ordinal":"3","NoteData":"2016-11-28","Type":"Other","Title":"Modified"}]}}}