CVE-2008-4391
Estado: ModificadaAlta (9.3)—
Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long invalid arguments.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.21%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- http://secunia.com/advisories/33032
- http://www.kb.cert.org/vuls/id/639345
- http://www.kb.cert.org/vuls/id/WDON-7M2U52
- http://www.securityfocus.com/bid/32665
- http://secunia.com/advisories/33032
- http://www.kb.cert.org/vuls/id/639345
- http://www.kb.cert.org/vuls/id/WDON-7M2U52
- http://www.securityfocus.com/bid/32665
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4391",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-12-09T00:30:00.267",
"references": [
{
"url": "http://secunia.com/advisories/33032",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/639345",
"tags": [
"Patch",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/WDON-7M2U52",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/32665",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/33032",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/639345",
"tags": [
"Patch",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/WDON-7M2U52",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32665",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long invalid arguments."
},
{
"lang": "es",
"value": "Desbordamiento de búfer basado en pila en el método SetSource del control ActiveX CamPlayerWeb11gv2 de NetCamPlayerWeb11gv2.ocx en la cámara de vídeo sin cables Cisco Linksys WVC54GC anterior al software empotrado (firmware) v1.25; permite a atacantes remotos ejecutar código de su elección a través de argumentos largos no válidos."
}
],
"lastModified": "2026-06-16T22:57:43.547",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:cisco:wvc54gc:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C882AB42-F04C-4968-A9C9-035A7411153E",
"versionEndIncluding": "1.19"
},
{
"criteria": "cpe:2.3:h:cisco:wvc54gc:1.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "39AE4F03-2623-476F-BFBF-5D458432BAEC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}