// For flags

CVE-2018-3937

 

Severity Score

7.2
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.

Existe una vulnerabilidad de inyección de comandos explotable en la funcionalidad measurementBitrateExec de Sony IPELA E Series Network Camera G5 con la versión 1.87.00 de firmware. Una petición GET especialmente manipulada podría provocar la ejecución de comandos arbitrarios. Un atacante puede enviar una petición HTTP manipulada para provocar esta vulnerabilidad.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-02 CVE Reserved
  • 2018-08-14 CVE Published
  • 2024-01-26 EPSS Updated
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sony
Search vendor "Sony"
Snc-eb600 Firmware
Search vendor "Sony" for product "Snc-eb600 Firmware"
1.87.00
Search vendor "Sony" for product "Snc-eb600 Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-eb600
Search vendor "Sony" for product "Snc-eb600"
--
Safe
Sony
Search vendor "Sony"
Snc-eb630 Firmware
Search vendor "Sony" for product "Snc-eb630 Firmware"
1.87.00
Search vendor "Sony" for product "Snc-eb630 Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-eb630
Search vendor "Sony" for product "Snc-eb630"
--
Safe
Sony
Search vendor "Sony"
Snc-eb600b Firmware
Search vendor "Sony" for product "Snc-eb600b Firmware"
1.87.00
Search vendor "Sony" for product "Snc-eb600b Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-eb600b
Search vendor "Sony" for product "Snc-eb600b"
--
Safe
Sony
Search vendor "Sony"
Snc-eb630b Firmware
Search vendor "Sony" for product "Snc-eb630b Firmware"
1.87.00
Search vendor "Sony" for product "Snc-eb630b Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-eb630b
Search vendor "Sony" for product "Snc-eb630b"
--
Safe
Sony
Search vendor "Sony"
Snc-eb602r Firmware
Search vendor "Sony" for product "Snc-eb602r Firmware"
1.87.00
Search vendor "Sony" for product "Snc-eb602r Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-eb602r
Search vendor "Sony" for product "Snc-eb602r"
--
Safe
Sony
Search vendor "Sony"
Snc-eb632r Firmware
Search vendor "Sony" for product "Snc-eb632r Firmware"
1.87.00
Search vendor "Sony" for product "Snc-eb632r Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-eb632r
Search vendor "Sony" for product "Snc-eb632r"
--
Safe
Sony
Search vendor "Sony"
Snc-em600 Firmware
Search vendor "Sony" for product "Snc-em600 Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em600 Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em600
Search vendor "Sony" for product "Snc-em600"
--
Safe
Sony
Search vendor "Sony"
Snc-em601 Firmware
Search vendor "Sony" for product "Snc-em601 Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em601 Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em601
Search vendor "Sony" for product "Snc-em601"
--
Safe
Sony
Search vendor "Sony"
Snc-em630 Firmware
Search vendor "Sony" for product "Snc-em630 Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em630 Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em630
Search vendor "Sony" for product "Snc-em630"
--
Safe
Sony
Search vendor "Sony"
Snc-em631 Firmware
Search vendor "Sony" for product "Snc-em631 Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em631 Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em631
Search vendor "Sony" for product "Snc-em631"
--
Safe
Sony
Search vendor "Sony"
Snc-em602r Firmware
Search vendor "Sony" for product "Snc-em602r Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em602r Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em602r
Search vendor "Sony" for product "Snc-em602r"
--
Safe
Sony
Search vendor "Sony"
Snc-em632r Firmware
Search vendor "Sony" for product "Snc-em632r Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em632r Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em632r
Search vendor "Sony" for product "Snc-em632r"
--
Safe
Sony
Search vendor "Sony"
Snc-em602rc Firmware
Search vendor "Sony" for product "Snc-em602rc Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em602rc Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em602rc
Search vendor "Sony" for product "Snc-em602rc"
--
Safe
Sony
Search vendor "Sony"
Snc-em632rc Firmware
Search vendor "Sony" for product "Snc-em632rc Firmware"
1.87.00
Search vendor "Sony" for product "Snc-em632rc Firmware" and version "1.87.00"
-
Affected
in Sony
Search vendor "Sony"
Snc-em632rc
Search vendor "Sony" for product "Snc-em632rc"
--
Safe