CVE-2018-7827

A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a users browser session.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
schneiderCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
schneider-electricd6220_firmware
2.11 ≤
schneider-electricd6220l_firmware
2.11 ≤
schneider-electricd6230_firmware
2.11 ≤
schneider-electricd6230l_firmware
2.11 ≤
schneider-electricimes19-1i_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1s_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1p_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1i_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1s_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1p_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1i_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1s_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1p_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1i_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1s_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1p_firmware
𝑥
< 2.2.3.0
schneider-electricime319-b1i_firmware
𝑥
< 2.2.3.0
schneider-electricime319-b1s_firmware
𝑥
< 2.2.3.0
schneider-electricime319-b1p_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1i_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-b1i_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1s_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-b1s_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1p_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-b1p_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1ei_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1es_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1ep_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1ei_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1es_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1ep_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1ei_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1es_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1ep_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1ei_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1es_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1ep_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1ei_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1es_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1ep_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1vi_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1vs_firmware
𝑥
< 2.2.3.0
schneider-electricimes19-1vp_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1vi_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1vs_firmware
𝑥
< 2.2.3.0
schneider-electricime119-1vp_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1vi_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1vs_firmware
𝑥
< 2.2.3.0
schneider-electricime219-1vp_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1vi_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1vs_firmware
𝑥
< 2.2.3.0
schneider-electricime319-1vp_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1vi_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1vs_firmware
𝑥
< 2.2.3.0
schneider-electricime3122-1vp_firmware
𝑥
< 2.2.3.0
schneider-electricixes1_firmware
𝑥
< 2.2.3.0
schneider-electricixe11_firmware
𝑥
< 2.2.3.0
schneider-electricixe21_firmware
𝑥
< 2.2.3.0
schneider-electricixe31_firmware
𝑥
< 2.2.3.0
𝑥
= Vulnerable software versions