← Back

CVE-2018-3937

nvd nist
Published: Aug 14, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.

Affected (14)

14 products
Snc Eb600 Firmware
Snc Eb630 Firmware
Snc Eb600b Firmware
Snc Eb630b Firmware
Snc Eb602r Firmware
Snc Eb632r Firmware
Snc Em600 Firmware
Snc Em601 Firmware
Snc Em630 Firmware
Snc Em631 Firmware
Snc Em602r Firmware
Snc Em632r Firmware
Snc Em602rc Firmware
Snc Em632rc Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Eb600
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Eb630
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Eb600b
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Eb630b
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Eb602r
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Eb632r
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em600
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em601
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em630
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em631
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em602r
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em632r
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em602rc
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.87.00
Running on/withPlatform Versions
Sony
Snc Em632rc
All versions

References (2)

Source: talos-cna@cisco.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.