Schneider-Electric Ime3122-1I Firmware vulnerabilities
6 known vulnerabilities affecting schneider-electric/ime3122-1i_firmware.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-7826HIGHCVSS 8.8fixed in 2.2.3.02019-05-22
CVE-2018-7826 [HIGH] CWE-77 CVE-2018-7826: A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Ca
A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.
nvd
CVE-2018-7825HIGHCVSS 8.8fixed in 2.2.3.02019-05-22
CVE-2018-7825 [HIGH] CWE-77 CVE-2018-7825: A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Cam
A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.
nvd
CVE-2018-7828HIGHCVSS 8.8fixed in 2.2.3.02019-05-22
CVE-2018-7828 [HIGH] CWE-352 CVE-2018-7828: A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into the camera.
nvd
CVE-2018-7829HIGHCVSS 8.8fixed in 2.2.3.02019-05-22
CVE-2018-7829 [HIGH] CWE-943 CVE-2018-7829: An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco S
An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which allows an attacker to execute arbitrary system commands.
nvd
CVE-2018-7816MEDIUMCVSS 6.5fixed in 2.2.3.02019-05-22
CVE-2018-7816 [MEDIUM] CVE-2018-7816: A Permissions, Privileges, and Access Control vulnerability exists in the web-based GUI of the 1st G
A Permissions, Privileges, and Access Control vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to delete an arbitrary file.
nvd
CVE-2018-7827MEDIUMCVSS 5.4fixed in 2.2.3.02019-05-22
CVE-2018-7827 [MEDIUM] CWE-79 CVE-2018-7827: A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Sp
A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session.
nvd