CVE-2018-7781

CWE-3113 documents3 sources
Severity
8.8HIGH
EPSS
0.1%
top 65.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateMay 13

Description

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages21 packages

CVEListV5schneider_electric_se/pelco_sarix_professional_v1Pelco Sarix Pro 1 st generation with firmware versions prior to 3.29.69

🔴Vulnerability Details

2
GHSA
GHSA-66q3-3329-6w7w: In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 32022-05-13
CVEList
CVE-2018-7781: In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 32018-07-03
CVE-2018-7781 (HIGH CVSS 8.8) | In Schneider Electric Pelco Sarix P | cvebase.io