acti records
6 published records for vendor acti.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-306 Missing Authentication for Critical Function1
- CWE-521 Weak Password Requirements1
- CWE-598 Use of HTTP Request With Sensitive Query String1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2017-3186No exploit | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all deacti · camera firmware · CWE-521 | Critical9.8 | — | 6.1% | Dec 15, 2017 |
41Plan | CVE-2017-3184No exploit | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory acti · camera firmware · CWE-306 | Critical9.8 | — | 5.9% | Dec 15, 2017 |
40Plan | CVE-2017-3185No exploit | ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method acti · camera firmware · CWE-598 | Critical9.8 | — | 3.2% | Dec 15, 2017 |
35Monitor | CVE-2020-15956Proof of concept | ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and applicacti · nvr · CWE-120 | High7.5 | — | 16.2% | Aug 4, 2020 |
33Monitor | CVE-2007-4582Proof of concept | Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (Nacti · network video recorder · CWE-119 | High7.5 | — | 10.0% | Aug 28, 2007 |
22Monitor | CVE-2007-4583Proof of concept | Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video acti · network video recorder · CWE-22 | Medium5.0 | — | 8.0% | Aug 28, 2007 |
- CVE-2017-318641Plan
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all de
CriticalCVSS 9.8No exploitEPSS 6%acti · camera firmwareDec 15, 2017
- CVE-2017-318441Plan
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory
CriticalCVSS 9.8No exploitEPSS 6%acti · camera firmwareDec 15, 2017
- CVE-2017-318540Plan
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method
CriticalCVSS 9.8No exploitEPSS 3%acti · camera firmwareDec 15, 2017
- CVE-2020-1595635Monitor
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and applic
HighCVSS 7.5Proof of conceptEPSS 16%acti · nvrAug 4, 2020
- CVE-2007-458233Monitor
Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (N
HighCVSS 7.5Proof of conceptEPSS 10%acti · network video recorderAug 28, 2007
- CVE-2007-458322Monitor
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video
MediumCVSS 5.0Proof of conceptEPSS 8%acti · network video recorderAug 28, 2007