ID

VAR-201801-1821


TITLE

Login bypass bypass vulnerability in pelco Sarix Pro webcam WEB management interface

Trust: 0.6

sources: CNVD: CNVD-2017-36509

DESCRIPTION

pelco Sarix Professional is a video camera. There is a login bypass vulnerability in the pelco Sarix Pro webcam WEB management interface. Allows an attacker to bypass password authentication and log in to the WEB management interface directly as an administrator.

Trust: 0.6

sources: CNVD: CNVD-2017-36509

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-36509

AFFECTED PRODUCTS

vendor:schneidermodel:electric sarix professional model: impscope:eqversion:-1110-103.29.65

Trust: 0.6

sources: CNVD: CNVD-2017-36509

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-36509
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2017-36509
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-36509

PATCH

title:Schneider Pelco Sarix Pro webcam WEB management interface has unauthorized access vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/107087

Trust: 0.6

sources: CNVD: CNVD-2017-36509

EXTERNAL IDS

db:CNVDid:CNVD-2017-36509

Trust: 0.6

sources: CNVD: CNVD-2017-36509

SOURCES

db:CNVDid:CNVD-2017-36509

LAST UPDATE DATE

2022-05-04T08:38:52.097000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-36509date:2017-12-07T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-36509date:2018-01-08T00:00:00