CVE-2018-3938
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
14/08/2018
Last modified:
19/04/2022
Description
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST request to trigger this vulnerability.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sony:snc-eb600_firmware:1.87.00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sony:snc-eb600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sony:snc-eb630_firmware:1.87.00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sony:snc-eb630:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sony:snc-eb600b_firmware:1.87.00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sony:snc-eb600b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sony:snc-eb630b_firmware:1.87.00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sony:snc-eb630b:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sony:snc-eb602r_firmware:1.87.00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sony:snc-eb602r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sony:snc-eb632r_firmware:1.87.00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sony:snc-eb632r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sony:snc-em600_firmware:1.87.00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sony:snc-em600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sony:snc-em601_firmware:1.87.00:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



