5.8
CVSSv2

CVE-2018-7236

Published: 09/03/2018 Updated: 02/02/2022
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions before 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric mps110-1_firmware

schneider-electric imps110-1er_firmware

schneider-electric ibps110-1er_firmware

schneider-electric imp1110-1_firmware

schneider-electric imp1110-1e_firmware

schneider-electric imp1110-1er_firmware

schneider-electric ibp1110-1er_firmware

schneider-electric imp219-1_firmware

schneider-electric imp219-1e_firmware

schneider-electric imp219-1er_firmware

schneider-electric ibp219-1er_firmware

schneider-electric imp319-1_firmware

schneider-electric imp319-1e_firmware

schneider-electric ibp319-1er_firmware

schneider-electric imp519-1_firmware

schneider-electric imp319-1er_firmware

schneider-electric imp519-1e_firmware

schneider-electric imp519-1er_firmware

schneider-electric ibp519-1er_firmware

schneider-electric imps110-1e_firmware