HIGH

CVE-2015-2098

CVSS v3

8.8

HIGH

EPSS Score

41.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4) AudioOnlySiteChannel function in the WESPPlayback.WESPPlaybackCtrl.1 control; (5) Connect or (6) ConnectEx function in the WESPPTZ.WESPPTZCtrl.1 control; (7) SiteChannel property in the WESPPlayback.WESPPlaybackCtrl.1 control; (8) SiteName property in the WESPPlayback.WESPPlaybackCtrl.1 control; or (9) OpenDVrSSite function in the WESPPTZ.WESPPTZCtrl.1 control.

Technical details

Published
7/22/2021

Frequently asked questions

What is CVE-2015-2098?

Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4) AudioOnlySiteChannel function in the WESPPlayback.WESPPlaybackCtrl.1 control; (5) Connect or (6) ConnectEx function in the WESPPTZ.WESPPTZCtrl.1 control; (7) SiteChannel property in the WESPPlayback.WESPPlaybackCtrl.1 control; (8) SiteName property in the WESPPlayback.WESPPlaybackCtrl.1 control; or (9) OpenDVrSSite function in the WESPPTZ.WESPPTZCtrl.1 control.

Is CVE-2015-2098 actively exploited?

Active exploitation of CVE-2015-2098 has not been confirmed. The EPSS score is 41.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2015-2098?

CVE-2015-2098 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2015-2098 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.