Privilege Escalation Vulnerability in Schneider Electric Pelco Sarix Professional Cameras
CVE-2018-7781

8.8HIGH

Key Information:

Vendor
CVE Published:
24 April 2018

Summary

A vulnerability exists in Schneider Electric's Pelco Sarix Professional 1st Generation cameras that allows an authenticated user to exploit a specially crafted request. This exploitation can lead to the exposure of passwords in clear text, thereby enabling unauthorized users to escalate their privileges and gain access to sensitive information. It is crucial for users to update their firmware to version 3.29.69 or later to mitigate this risk.

Affected Version(s)

Pelco Sarix Professional V1 Pelco Sarix Pro 1 st generation with firmware versions prior to 3.29.69

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.