CVE-2018-7234
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.
Affected (20)
Products: Schneider Electric: Mps110 1 Firmware, Imps110 1er Firmware, Ibps110 1er Firmware, Imp1110 1 Firmware, Imp1110 1e Firmware, Imp1110 1er Firmware, Ibp1110 1er Firmware, Imp219 1 Firmware, Imp219 1e Firmware, Imp219 1er Firmware, Ibp219 1er Firmware, Imp319 1 Firmware, Imp319 1e Firmware, Ibp319 1er Firmware, Imp519 1 Firmware, Imp319 1er Firmware, Imp519 1e Firmware, Imp519 1er Firmware, Ibp519 1er Firmware, Imps110 1e Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Mps110 1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imps110 1er | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Ibps110 1er | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp1110 1 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp1110 1e | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp1110 1er | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Ibp1110 1er | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp219 1 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp219 1e | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp219 1er | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Ibp219 1er | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp319 1 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp319 1e | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Ibp319 1er | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp519 1 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp319 1er | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp519 1e | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imp519 1er | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Ibp519 1er | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.29.67 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Imps110 1e | All versions |
References (2)
Source: cybersecurity@se.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.