CVE-2018-7227

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
schneiderCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
schneider-electricmps110-1_firmware
𝑥
< 3.29.67
schneider-electricimps110-1er_firmware
𝑥
< 3.29.67
schneider-electricibps110-1er_firmware
𝑥
< 3.29.67
schneider-electricimp1110-1_firmware
𝑥
< 3.29.67
schneider-electricimp1110-1e_firmware
𝑥
< 3.29.67
schneider-electricimp1110-1er_firmware
𝑥
< 3.29.67
schneider-electricibp1110-1er_firmware
𝑥
< 3.29.67
schneider-electricimp219-1_firmware
𝑥
< 3.29.67
schneider-electricimp219-1e_firmware
𝑥
< 3.29.67
schneider-electricimp219-1er_firmware
𝑥
< 3.29.67
schneider-electricibp219-1er_firmware
𝑥
< 3.29.67
schneider-electricimp319-1_firmware
𝑥
< 3.29.67
schneider-electricimp319-1e_firmware
𝑥
< 3.29.67
schneider-electricibp319-1er_firmware
𝑥
< 3.29.67
schneider-electricimp519-1_firmware
𝑥
< 3.29.67
schneider-electricimp319-1er_firmware
𝑥
< 3.29.67
schneider-electricimp519-1e_firmware
𝑥
< 3.29.67
schneider-electricimp519-1er_firmware
𝑥
< 3.29.67
schneider-electricibp519-1er_firmware
𝑥
< 3.29.67
schneider-electricimps110-1e_firmware
𝑥
< 3.29.67
𝑥
= Vulnerable software versions