6.4
CVSSv2

CVE-2018-7237

Published: 09/03/2018 Updated: 02/02/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions before 3.29.67 which could allow a remote malicious user to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric mps110-1_firmware

schneider-electric imps110-1er_firmware

schneider-electric ibps110-1er_firmware

schneider-electric imp1110-1_firmware

schneider-electric imp1110-1e_firmware

schneider-electric imp1110-1er_firmware

schneider-electric ibp1110-1er_firmware

schneider-electric imp219-1_firmware

schneider-electric imp219-1e_firmware

schneider-electric imp219-1er_firmware

schneider-electric ibp219-1er_firmware

schneider-electric imp319-1_firmware

schneider-electric imp319-1e_firmware

schneider-electric ibp319-1er_firmware

schneider-electric imp519-1_firmware

schneider-electric imp319-1er_firmware

schneider-electric imp519-1e_firmware

schneider-electric imp519-1er_firmware

schneider-electric ibp519-1er_firmware

schneider-electric imps110-1e_firmware