A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.

Subscriptions

Vendors Products
Schneider-electric Subscribe
Ibp1110-1er Subscribe
Ibp1110-1er Firmware Subscribe
Ibp219-1er Subscribe
Ibp219-1er Firmware Subscribe
Ibp319-1er Subscribe
Ibp319-1er Firmware Subscribe
Ibp519-1er Subscribe
Ibp519-1er Firmware Subscribe
Ibps110-1er Subscribe
Ibps110-1er Firmware Subscribe
Imp1110-1 Subscribe
Imp1110-1 Firmware Subscribe
Imp1110-1e Subscribe
Imp1110-1e Firmware Subscribe
Imp1110-1er Subscribe
Imp1110-1er Firmware Subscribe
Imp219-1 Subscribe
Imp219-1 Firmware Subscribe
Imp219-1e Subscribe
Imp219-1e Firmware Subscribe
Imp219-1er Subscribe
Imp219-1er Firmware Subscribe
Imp319-1 Subscribe
Imp319-1 Firmware Subscribe
Imp319-1e Subscribe
Imp319-1e Firmware Subscribe
Imp319-1er Subscribe
Imp319-1er Firmware Subscribe
Imp519-1 Subscribe
Imp519-1 Firmware Subscribe
Imp519-1e Subscribe
Imp519-1e Firmware Subscribe
Imp519-1er Subscribe
Imp519-1er Firmware Subscribe
Imps110-1e Subscribe
Imps110-1e Firmware Subscribe
Imps110-1er Subscribe
Imps110-1er Firmware Subscribe
Mps110-1 Subscribe
Mps110-1 Firmware Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-18975 A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-09-16T20:22:19.073Z

Reserved: 2018-02-19T00:00:00.000Z

Link: CVE-2018-7236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-09T23:29:00.810

Modified: 2024-11-21T04:11:50.863

Link: CVE-2018-7236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses