Privilege Escalation Vulnerability in Schneider Electric Pelco Sarix Professional Cameras
CVE-2018-7781
8.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 24 April 2018
Summary
A vulnerability exists in Schneider Electric's Pelco Sarix Professional 1st Generation cameras that allows an authenticated user to exploit a specially crafted request. This exploitation can lead to the exposure of passwords in clear text, thereby enabling unauthorized users to escalate their privileges and gain access to sensitive information. It is crucial for users to update their firmware to version 3.29.69 or later to mitigate this risk.
Affected Version(s)
Pelco Sarix Professional V1 Pelco Sarix Pro 1 st generation with firmware versions prior to 3.29.69
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved