CVE-2020-15956: Acti NVR

High severity, CVSS 7.5. EPSS: 16.2% chance of exploitation in the next 30 days.

ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.

Affected products

  • Acti NVR: version 2.3.04.07 only; version 3.0.12.42 only

Published 2020-08-04. Last modified 2026-06-17.