CVE-2014-8756: Medium severity panasonic network camera recorder firmware vulnerability
Published Oct 17, 2014
·Updated
The NcrCtl4.NcrNet.1 control in Panasonic Network Camera Recorder before 4.04R03 allows remote attackers to execute arbitrary code via a crafted GetVOLHeader method call, which writes null bytes to an arbitrary address.
Affected Software
2 affected components
Panasonic Network Camera Recorder Firmware<4.04r03
Panasonic Network Camera Recorder
Remediation
Event History
Oct 17, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8756?
CVE-2014-8756 has a severity rating of high due to its potential for remote code execution.
2
How do I fix CVE-2014-8756?
To fix CVE-2014-8756, upgrade to Panasonic Network Camera Recorder firmware version 4.04R03 or later.
3
What types of attacks can exploit CVE-2014-8756?
CVE-2014-8756 can be exploited by attackers to execute arbitrary code remotely through a crafted GetVOLHeader method call.
4
Which versions of Panasonic Network Camera Recorder are affected by CVE-2014-8756?
Panasonic Network Camera Recorder versions prior to 4.04R03 are affected by CVE-2014-8756.
5
Is there a workaround for CVE-2014-8756?
Currently, there are no known workarounds for CVE-2014-8756 other than applying the firmware update.