CVE-2017-9966
7.1HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 2 January 2018
Summary
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.
Affected Version(s)
Pelco VideoXpert Enterprise Versions 2.0 and prior
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved