CVE-2014-1201
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.
Published:Jan 15, 2014
Last Modified:Apr 11, 2025
EPS:Jan 15, 2014
EPSS Score:0.24982
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Lorex Technology
Product
Edge2 Lh330 Firmware
Lorex Technology
Edge2 Lh330 Firmware
Vendor
Lorex Technology
Product
Edge3 Lh340 Firmware
Lorex Technology
Edge3 Lh340 Firmware
Vendor
Lorex Technology
Product
Edge\+ Lh320 Firmware
Lorex Technology
Edge\+ Lh320 Firmware
Vendor
Lorex Technology
Product
Edge Lh310 Firmware
Lorex Technology
Edge Lh310 Firmware
Vendor
Lorextechnology
Product
Edge
Lorextechnology
Edge
Vendor
Lorextechnology
Product
Edge2
Lorextechnology
Edge2
Vendor
Lorextechnology
Product
Edge3
Lorextechnology
Edge3
Vendor
Lorextechnology
Product
Edge\+
Lorextechnology
Edge\+
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
