An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.

Project Subscriptions

Vendors Products
Snc-eb600 Subscribe
Snc-eb600 Firmware Subscribe
Snc-eb600b Subscribe
Snc-eb600b Firmware Subscribe
Snc-eb602r Subscribe
Snc-eb602r Firmware Subscribe
Snc-eb630 Subscribe
Snc-eb630 Firmware Subscribe
Snc-eb630b Subscribe
Snc-eb630b Firmware Subscribe
Snc-eb632r Subscribe
Snc-eb632r Firmware Subscribe
Snc-em600 Subscribe
Snc-em600 Firmware Subscribe
Snc-em601 Subscribe
Snc-em601 Firmware Subscribe
Snc-em602r Subscribe
Snc-em602r Firmware Subscribe
Snc-em602rc Subscribe
Snc-em602rc Firmware Subscribe
Snc-em630 Subscribe
Snc-em630 Firmware Subscribe
Snc-em631 Subscribe
Snc-em631 Firmware Subscribe
Snc-em632r Subscribe
Snc-em632r Firmware Subscribe
Snc-em632rc Subscribe
Snc-em632rc Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2024-09-16T16:13:19.122Z

Reserved: 2018-01-02T00:00:00

Link: CVE-2018-3937

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-14T19:29:01.027

Modified: 2024-11-21T04:06:20.387

Link: CVE-2018-3937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses