peter bassill · operator
$ cve CVE-2015-2097 JSON

CVE-2015-2097 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 24.1% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect function in the (4) WESPSerialPort.WESPSerialPortCtrl.1 or (5) WESPPLAYBACKLib.WESPPlaybackCtrl control, or (6) AddID function in the WESPCONFIGLib.IDList control or a (7) long string to the second argument to the ConnectEx3 function in the WESPPLAYBACKLib.WESPPlaybackCtrl control.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS24.14% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2015-03-09
Last modified2026-06-17

Affected (1)

VendorProduct
webgatewebgate embedded standard protocol sdk

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD