CVE-2018-7781

In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
schneiderCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
VendorProductVersion
schneider-electricimps110-1_firmware
𝑥
< 3.29.69
schneider-electricimps110-1e_firmware
𝑥
< 3.29.69
schneider-electricimps110-1er_firmware
𝑥
< 3.29.69
schneider-electricibps110-1er_firmware
𝑥
< 3.29.69
schneider-electricimp1110-1_firmware
𝑥
< 3.29.69
schneider-electricimp1110-1e_firmware
𝑥
< 3.29.69
schneider-electricimp1110-1er_firmware
𝑥
< 3.29.69
schneider-electricibp1110-1er_firmware
𝑥
< 3.29.69
schneider-electricimp219-1_firmware
𝑥
< 3.29.69
schneider-electricimp219-1e_firmware
𝑥
< 3.29.69
schneider-electricimp219-1er_firmware
𝑥
< 3.29.69
schneider-electricibp219-1er_firmware
𝑥
< 3.29.69
schneider-electricimp319-1_firmware
𝑥
< 3.29.69
schneider-electricimp319-1e_firmware
𝑥
< 3.29.69
schneider-electricimp319-1er_firmware
𝑥
< 3.29.69
schneider-electricibp319-1er_firmware
𝑥
< 3.29.69
schneider-electricimp519-1_firmware
𝑥
< 3.29.69
schneider-electricimp519-1e_firmware
𝑥
< 3.29.69
schneider-electricimp519-1er_firmware
𝑥
< 3.29.69
schneider-electricibp519-1er_firmware
𝑥
< 3.29.69
𝑥
= Vulnerable software versions