A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.

Project Subscriptions

Vendors Products
Schneider-electric Subscribe
Ibp1110-1er Subscribe
Ibp1110-1er Firmware Subscribe
Ibp219-1er Subscribe
Ibp219-1er Firmware Subscribe
Ibp319-1er Subscribe
Ibp319-1er Firmware Subscribe
Ibp519-1er Subscribe
Ibp519-1er Firmware Subscribe
Ibps110-1er Subscribe
Ibps110-1er Firmware Subscribe
Imp1110-1 Subscribe
Imp1110-1 Firmware Subscribe
Imp1110-1e Subscribe
Imp1110-1e Firmware Subscribe
Imp1110-1er Subscribe
Imp1110-1er Firmware Subscribe
Imp219-1 Subscribe
Imp219-1 Firmware Subscribe
Imp219-1e Subscribe
Imp219-1e Firmware Subscribe
Imp219-1er Subscribe
Imp219-1er Firmware Subscribe
Imp319-1 Subscribe
Imp319-1 Firmware Subscribe
Imp319-1e Subscribe
Imp319-1e Firmware Subscribe
Imp319-1er Subscribe
Imp319-1er Firmware Subscribe
Imp519-1 Subscribe
Imp519-1 Firmware Subscribe
Imp519-1e Subscribe
Imp519-1e Firmware Subscribe
Imp519-1er Subscribe
Imp519-1er Firmware Subscribe
Imps110-1e Subscribe
Imps110-1e Firmware Subscribe
Imps110-1er Subscribe
Imps110-1er Firmware Subscribe
Mps110-1 Subscribe
Mps110-1 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-18975 A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-09-16T20:22:19.073Z

Reserved: 2018-02-19T00:00:00.000Z

Link: CVE-2018-7236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-09T23:29:00.810

Modified: 2024-11-21T04:11:50.863

Link: CVE-2018-7236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses