CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreNov 21, 2024 May 22, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which allows an attacker to execute arbitrary system commands. |
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreNov 21, 2024 May 22, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into...Show more |
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreNov 21, 2024 May 22, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session...Show more |
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreNov 21, 2024 May 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands. |
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreNov 21, 2024 May 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands. |
1Schneider Electric 59D6220 Firmware D6220l FirmwareD6230 Firmware+56 moreNov 21, 2024 May 22, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A Permissions, Privileges, and Access Control vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to delete an arbitrary file. |