CVE-2017-9966
published 2018-01-02CVE-2017-9966: A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an…
PriorityP434high7.1CVSS 3.0
AVNACHPRLUIRSUCHIHAH
EPSS
1.62%
73.3th percentile
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | pelco_videoxpert | < 2.1 | 2.1 |
| schneider_electric_se | pelco_videoxpert_enterprise | — | — |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric Pelco VideoXpert Enterprise
cisa_ics·2017-12-21
Schneider Electric Pelco VideoXpert Enterprise
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Pelco VideoXpert Enterprise
Last RevisedDecember 21, 2017
Alert CodeICSA-17-355-02
## CVSS v3 7.1
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Schneider Electric
Equipment: Pelco VideoXpert Enterprise
Vulnerabilities: Path Traversal, Improper Access Control
## AFFECTED PRODUCTS
Schneider Electric reports that the vulnerabilities affect the following Pelco VideoXpert Enterprise products:
- Pelco VideoXpert Enterprise all versions prior to 2.1
## IMPACT
Successful exploitation of these vulnerabilities may allow an authorized user t
GHSA
GHSA-5fp8-73jr-79h2: A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2
ghsa_unreviewed·2022-05-13
CVE-2017-9966 [HIGH] GHSA-5fp8-73jr-79h2: A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102338https://ics-cert.us-cert.gov/advisories/ICSA-17-355-02https://www.schneider-electric.com/en/download/document/SEVD-2017-339-01/http://www.securityfocus.com/bid/102338https://ics-cert.us-cert.gov/advisories/ICSA-17-355-02https://www.schneider-electric.com/en/download/document/SEVD-2017-339-01/
2018-01-02
Published