CVE-2018-3937: Command Injection
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-3937?
CVE-2018-3937 is a command injection vulnerability in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00.
How does CVE-2018-3937 impact Sony IPELA E Series Network Camera G5 firmware 1.87.00?
CVE-2018-3937 allows an attacker to execute arbitrary commands by sending a specially crafted GET request.
What is the severity of CVE-2018-3937?
CVE-2018-3937 has a severity rating of 7.2 (out of 10).
Which versions of Sony IPELA E Series Network Camera G5 firmware are affected by CVE-2018-3937?
Sony IPELA E Series Network Camera G5 firmware 1.87.00 is affected by CVE-2018-3937.
Is Sony Snc-eb600 vulnerable to CVE-2018-3937?
Yes, Sony Snc-eb600 with firmware version 1.87.00 is vulnerable to CVE-2018-3937.