ID

VAR-201708-1638


TITLE

Schneider Electric Pelco Sarix/Spectra Cameras Remote Code Execution Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-23309

DESCRIPTION

PelcoSarix/SpectraCameras is a camera. A remote code execution vulnerability exists in SchneiderElectricPelcoSarix/SpectraCameras. A remote attacker can exploit the vulnerability to execute arbitrary system commands, authorize the system to access using root privileges, and use specially crafted request and escape sequences to the system shell.

Trust: 0.6

sources: CNVD: CNVD-2017-23309

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-23309

AFFECTED PRODUCTS

vendor:schneidermodel:electric spectra enhanced model: d6230 2.2.0.5.9340-a0.0scope:eqversion: -

Trust: 0.6

vendor:schneidermodel:electric sarix model: id10dn 1.8.2.18-20121109-1.9110-o3.8503scope:eqversion: -

Trust: 0.6

vendor:schneidermodel:electric sarix model: d5230 1.9.2.23-20141118-1.9330-a1.10722scope:eqversion: -

Trust: 0.6

vendor:schneidermodel:electric sarix enhanced model: ime119 2.1.2.0.8280-a0.0scope:eqversion: -

Trust: 0.6

vendor:schneidermodel:electric sarix enhanced model: ime219 2.1.2.0.8280-a0.0scope:eqversion: -

Trust: 0.6

sources: CNVD: CNVD-2017-23309

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-23309
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-23309
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-23309

EXTERNAL IDS

db:EXPLOITALERTid:27111

Trust: 0.6

db:CNVDid:CNVD-2017-23309

Trust: 0.6

sources: CNVD: CNVD-2017-23309

REFERENCES

url:http://www.exploitalert.com/view-details.html?id=27111

Trust: 0.6

sources: CNVD: CNVD-2017-23309

SOURCES

db:CNVDid:CNVD-2017-23309

LAST UPDATE DATE

2022-05-17T02:08:57.661000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-23309date:2017-08-28T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-23309date:2017-08-28T00:00:00