CVE-2018-7237
09.03.2018, 23:29
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'Enginsight
Vendor | Product | Version |
---|---|---|
schneider-electric | mps110-1_firmware | 𝑥 < 3.29.67 |
schneider-electric | imps110-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | ibps110-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp1110-1_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp1110-1e_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp1110-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | ibp1110-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp219-1_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp219-1e_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp219-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | ibp219-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp319-1_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp319-1e_firmware | 𝑥 < 3.29.67 |
schneider-electric | ibp319-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp519-1_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp319-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp519-1e_firmware | 𝑥 < 3.29.67 |
schneider-electric | imp519-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | ibp519-1er_firmware | 𝑥 < 3.29.67 |
schneider-electric | imps110-1e_firmware | 𝑥 < 3.29.67 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration