6.8
CVSSv2

CVE-2018-7230

Published: 09/03/2018 Updated: 02/02/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions before 3.29.67.

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric mps110-1_firmware

schneider-electric imps110-1er_firmware

schneider-electric ibps110-1er_firmware

schneider-electric imp1110-1_firmware

schneider-electric imp1110-1e_firmware

schneider-electric imp1110-1er_firmware

schneider-electric ibp1110-1er_firmware

schneider-electric imp219-1_firmware

schneider-electric imp219-1e_firmware

schneider-electric imp219-1er_firmware

schneider-electric ibp219-1er_firmware

schneider-electric imp319-1_firmware

schneider-electric imp319-1e_firmware

schneider-electric ibp319-1er_firmware

schneider-electric imp519-1_firmware

schneider-electric imp319-1er_firmware

schneider-electric imp519-1e_firmware

schneider-electric imp519-1er_firmware

schneider-electric ibp519-1er_firmware

schneider-electric imps110-1e_firmware