CVE-2024-46461
CVSS 8 HIGH: vLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). EPSS 0.6% (47th percentile).
Vulnerabilities & Exploits · Supply Chain
Patching VLC on its own does not clear ABB Ability Camera Connect. The vulnerable copy lives inside ABB’s installer, so Camera Connect stays exposed until ABB updates the embedded component or the product to 1.5.0.15.
ABB says Camera Connect versions 1.5.0.14 and below shipped with VLC 2.2.4, which is affected by CVE-2024-46461. A malicious MMS stream could trigger an integer overflow that can crash VLC or potentially lead to arbitrary code execution with the target user’s privileges.
The practical risk is a false sense of closure from normal app-level patch tracking. In fleets that rely on vendor-packaged libraries, the upstream fix and the deployed fix are not the same thing.
1 source · May 26
CVSS 8 HIGH: vLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). EPSS 0.6% (47th percentile).
CISA Advisories
ABB Ability Camera Connect | CISA
ABB Ability Camera Connect Summary ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below.
originalPart of the PlainSec briefing for 2026-05-26
Every edition of this story: ABB Camera Connect Needs Its Own VLC Fix