CVE-2017-9966Improper Privilege Management in Pelco Videoxpert

3 documents3 sources
Severity
7.1HIGHNVD
EPSS
0.5%
top 32.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateMay 13

Description

A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5fp8-73jr-79h2: A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 22022-05-13
CVEList
CVE-2017-9966: A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 22018-01-02
CVE-2017-9966 — Improper Privilege Management | cvebase