CVE-2014-9596
https://notcve.org/view.php?id=CVE-2014-9596
Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU before 9.3.1 build 4.08.003.0, when USB Wi-Fi or Direct LAN is enabled, and MK 3.0 VPU before 9.3.1 build 5.06.000.0, when Embedded Wi-Fi or Direct LAN is enabled, does not use encryption, which allows remote attackers to obtain sensitive information by sniffing the network for client-server traffic, as demonstrated by Active Directory credential information. Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU anterior a 9.3.1 build 4.08.003.0, cuando USB Wi-Fi o Direct LAN está habilitado, y MK 3.0 VPU anterior a 9.3.1 build 5.06.000.0, cuando Embedded Wi-Fi o Direct LAN está habilitado, no utiliza cifrado, lo que permite a atacantes remotos obtener información sensible mediante la captura de trafico del servidor cliente de la red, tal y como fue demostrado por información de credenciales de Active Directory. • http://us2.campaign-archive1.com/?u=8c9cff2e712e3b7d09a07ecef&id=21f059b3ab http://www.kb.cert.org/vuls/id/117604 • CWE-310: Cryptographic Issues •
CVE-2014-8756 – Panasonic Network Camera Recorder NcrCtl4.NcrNet.1 GetVOLHeader Arbitrary Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2014-8756
The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address. El control NcrCtl4.NcrNet.1 en Panasonic Network Camera Recorder anterior a 4.04R03 permite a atacantes remotos ejecutar código arbitrario a través de una llamada manipulada al método GetVOLHeader, escribiendo bytes nulos en una dirección arbitraria. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Panasonic Network Camera Recorder. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within then NcrCtl4.NcrNet.1 control. The GetVOLHeader method can be used to write null bytes to an arbitrary address. • http://panasonic.net/pcc/cgi-bin/products/netwkcam/download_us/tbookmarka_m.cgi?m=%20&mm=2010073014092324 http://www.zerodayinitiative.com/advisories/ZDI-14-363 •
CVE-2014-8755 – Panasonic Network Camera View GetImageDataPrint Untrusted Pointer Dereference Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2014-8755
Panasonic Network Camera View 3 and 4 allows remote attackers to execute arbitrary code via a crafted page, which triggers an invalid pointer dereference, related to "the ability to nullify an arbitrary address in memory." Panasonic Network Camera View 3 y 4 permite a atacantes remotos ejecutar código arbitrario a través de una página manipulada, lo que provoca una referencia a puntero inválida, relacionado con 'la habilidad de anular una dirección arbitraria en la memoria.' This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Panasonic Network Camera View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the GetImageDataPrint method of the WebVideoCam ActiveX control. The issue lies in the ability to nullify an arbitrary address in memory. • http://security.panasonic.com/pss/security/library/howto_update_NCV.html http://www.zerodayinitiative.com/advisories/ZDI-14-364 • CWE-20: Improper Input Validation •
CVE-2008-3482
https://notcve.org/view.php?id=CVE-2008-3482
Cross-site scripting (XSS) vulnerability in the error page feature in Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, and BB-HCM515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en la característica de la página de error en Panasonic Network Camera BL-C111, BL-C131, BB-HCM511, BB-HCM531, BB-HCM580, BB-HCM581, BB-HCM527, y BB-HCM515, que permite a los atacantes remotos insertar arbitrariamente una secuencia web o HTML a través de vestores no especificados. • http://jvn.jp/en/jp/JVN33706820/index.html http://jvndb.jvn.jp/contents/ja/2008/JVNDB-2008-000037.html http://panasonic.net/pcc/support/netwkcam/support/info_xss.html http://secunia.com/advisories/31304 http://www.vupen.com/english/advisories/2008/2257/references https://exchange.xforce.ibmcloud.com/vulnerabilities/44118 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •