CVE-2018-3937
14.08.2018, 19:29
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.
Vendor | Product | Version |
---|---|---|
sony | snc-eb600_firmware | 1.87.00 |
sony | snc-eb630_firmware | 1.87.00 |
sony | snc-eb600b_firmware | 1.87.00 |
sony | snc-eb630b_firmware | 1.87.00 |
sony | snc-eb602r_firmware | 1.87.00 |
sony | snc-eb632r_firmware | 1.87.00 |
sony | snc-em600_firmware | 1.87.00 |
sony | snc-em601_firmware | 1.87.00 |
sony | snc-em630_firmware | 1.87.00 |
sony | snc-em631_firmware | 1.87.00 |
sony | snc-em602r_firmware | 1.87.00 |
sony | snc-em632r_firmware | 1.87.00 |
sony | snc-em602rc_firmware | 1.87.00 |
sony | snc-em632rc_firmware | 1.87.00 |
𝑥
= Vulnerable software versions