Privilege Escalation Vulnerability in Schneider Electric's Pelco VideoXpert
CVE-2017-9966
7.1HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 2 January 2018
Summary
A privilege escalation vulnerability in Schneider Electric’s Pelco VideoXpert Enterprise allows unauthorized users to gain elevated system privileges by replacing specific files. This exploit enables the execution of malicious code at an elevated privilege level, potentially compromising the security of the entire system. Organizations using affected versions are advised to apply the relevant updates and security measures to mitigate the risk of exploitation.
Affected Version(s)
Pelco VideoXpert Enterprise Versions 2.0 and prior
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved