CVE-2014-1201 - CVE House
Back to Database
Status published Critical CVE-2014-1201

Buffer overflow in the INetViewX ActiveX control in the Lorex...

Vulnerability Description

Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-1201

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

lorex technology

View all reports →

Affected Software

edge lh310 firmware, edge, edge3 lh340 firmware, edge3, edge2 lh330 firmware, edge2, edge\+ lh320 firmware, edge\+
Vulnerable Versions:
7-35-28-1b26e, lh310, 11.19.85_1fe3a, lh340, 11.17.38-33_1d97a, lh330, lh320

Timeline

Official Publish: January 15th, 2014
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.