CVE-2017-9964
published 2018-01-02CVE-2017-9964: A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized…
PriorityP337medium6.9CVSS 3.0
AVNACHPRNUIRSCCLIHAN
EPSS
1.99%
78.6th percentile
A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | pelco_videoxpert | < 2.1 | 2.1 |
| schneider_electric_se | pelco_videoxpert_enterprise | — | — |
CVSS provenance
nvdv3.06.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Pelco VideoXpert Enterprise
cisa_ics·2017-12-21
Schneider Electric Pelco VideoXpert Enterprise
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Pelco VideoXpert Enterprise
Last RevisedDecember 21, 2017
Alert CodeICSA-17-355-02
## CVSS v3 7.1
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Schneider Electric
Equipment: Pelco VideoXpert Enterprise
Vulnerabilities: Path Traversal, Improper Access Control
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerabilities affect the following Pelco VideoXpert Enterprise products:
- Pelco VideoXpert Enterprise all versions prior to 2.1
## IMPACT
Successful exploitation of these vulnerabilities may allow an authorized user t
GHSA
GHSA-rq56-32m2-gfc7: A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2
ghsa_unreviewed·2022-05-14
CVE-2017-9964 [MEDIUM] CWE-22 GHSA-rq56-32m2-gfc7: A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2
A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102338https://ics-cert.us-cert.gov/advisories/ICSA-17-355-02https://www.schneider-electric.com/en/download/document/SEVD-2017-339-01/http://www.securityfocus.com/bid/102338https://ics-cert.us-cert.gov/advisories/ICSA-17-355-02https://www.schneider-electric.com/en/download/document/SEVD-2017-339-01/
2018-01-02
Published