Page 2 of 12 results (0.002 seconds)

CVSS: 8.1EPSS: 0%CPEs: 40EXPL: 0

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service. Existe una vulnerabilidad en Pelco Sarix Professional de Schneider Electric en todas las versiones de firmware anteriores a la 3.29.67 que podría habilitar el servicio SSH debido a la falta de autenticación de /login/bin/set_param. • https://www.schneider-electric.com/en/download/document/SEVD-2018-058-01 • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 0%CPEs: 40EXPL: 0

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges. Existe una vulnerabilidad en Pelco Sarix Professional de Schneider Electric en todas las versiones de firmware anteriores a la 3.29.67 que podría permitir que un atacante remoto no autenticado omita la autenticación y obtenga privilegios de administrador. • https://www.schneider-electric.com/en/download/document/SEVD-2018-058-01 • CWE-287: Improper Authentication •

CVSS: 8.8EPSS: 0%CPEs: 40EXPL: 0

A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67. Existe una vulnerabilidad de XEE (XML External Entity) en import.cgi del componente de la interfaz web en Pelco Sarix Professional de Schneider Electric en todas las versiones de firmware anteriores a la 3.29.67. • https://www.schneider-electric.com/en/download/document/SEVD-2018-058-01 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 9.8EPSS: 0%CPEs: 40EXPL: 0

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'network.ieee8021x.delete_certs'. Existe una vulnerabilidad en Pelco Sarix Professional de Schneider Electric en todas las versiones de firmware anteriores a la 3.29.67 que podría permitir la ejecución de comandos debido a la falta de validación de los metacaracteres shell con el valor "network.ieee8021x.delete_certs". • https://www.schneider-electric.com/en/download/document/SEVD-2018-058-01 • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 0%CPEs: 40EXPL: 0

A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate. Existe una vulnerabilidad en Pelco Sarix Professional de Schneider Electric en todas las versiones de firmware anteriores a la 3.29.67 que podría permitir la descarga arbitraria de archivos del sistema debido a la falta de validación de certificados SSL. • https://www.schneider-electric.com/en/download/document/SEVD-2018-058-01 • CWE-295: Improper Certificate Validation •