← Vulnerability feed

Vulnerability record · CVE-2002-1643 · published 19 December 2002

CVE-2002-1643: RealNetworks Helix Universal Server RTSP/HTTP buffer overflows allow remote code execution

RRealnetworks · Helix Universal Server

RealNetworks Helix Universal Server 9.0 (9.0.2.768) contains multiple buffer overflows reachable over the network. A long Transport field in a SETUP RTSP request, a DESCRIBE RTSP request with a long URL argument, or two simultaneous HTTP GET requests with long arguments can overflow buffers. The flaw matters because it permits unauthenticated remote code execution against a media streaming server.

7.5 CVSS 2.0 High EPSS 75% · top 0.5%
7.5CVSS 2.0 base score
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though the product is legacy and not in KEV.

What it is

RealNetworks Helix Universal Server 9.0 (9.0.2.768) contains multiple buffer overflows reachable over the network. A long Transport field in a SETUP RTSP request, a DESCRIBE RTSP request with a long URL argument, or two simultaneous HTTP GET requests with long arguments can overflow buffers. The flaw matters because it permits unauthenticated remote code execution against a media streaming server.

Impact

An attacker can execute arbitrary code with the privileges of the Helix Universal Server process, potentially leading to full compromise of the host. No privilege escalation or local access is required beyond network reachability.

Attack surface

Reached over the network via RTSP (SETUP, DESCRIBE) and HTTP requests to the server's listening ports. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.747 (99.5th percentile) and one reference is tagged Exploit, indicating public exploit code exists and exploitation is likely.

What to do

  • Apply the vendor patch referenced in the RealNetworks security advisory and CERT/CC VU#974689.
  • Upgrade to a fixed Helix Universal Server version if the 9.0.2.768 build is still in use.
  • Restrict network access to RTSP and HTTP management/streaming ports to trusted sources only.
  • Monitor vendor advisories for any further updates, as the product is legacy and may be unsupported.

Detection

  • Inspect RTSP traffic for SETUP requests with abnormally long Transport headers or DESCRIBE requests with unusually long URL arguments.
  • Look for pairs of simultaneous HTTP GET requests containing long arguments to the Helix server.
  • Monitor server process crashes or unexpected restarts that could indicate failed overflow attempts.
  • Review network logs for scanning or exploit traffic targeting RTSP (typically TCP 554) and HTTP ports on Helix hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1643 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2002-1643), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.