CVE-2018-7234
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
09/03/2018
Last modified:
02/02/2022
Description
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:schneider-electric:mps110-1_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) | |
| cpe:2.3:h:schneider-electric:mps110-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:imps110-1er_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) | |
| cpe:2.3:h:schneider-electric:imps110-1er:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:ibps110-1er_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) | |
| cpe:2.3:h:schneider-electric:ibps110-1er:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:imp1110-1_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) | |
| cpe:2.3:h:schneider-electric:imp1110-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:imp1110-1e_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) | |
| cpe:2.3:h:schneider-electric:imp1110-1e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:imp1110-1er_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) | |
| cpe:2.3:h:schneider-electric:imp1110-1er:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:ibp1110-1er_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) | |
| cpe:2.3:h:schneider-electric:ibp1110-1er:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:schneider-electric:imp219-1_firmware:*:*:*:*:*:*:*:* | 3.29.67 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



