First published: Tue Aug 14 2018(Updated: )
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sony Snc-eb600 Firmware | =1.87.00 | |
Sony Snc-eb600 | ||
Sony Snc-eb630 Firmware | =1.87.00 | |
Sony Snc-eb630 | ||
Sony Snc-eb600b Firmware | =1.87.00 | |
Sony Snc-eb600b | ||
Sony Snc-eb630b Firmware | =1.87.00 | |
Sony Snc-eb630b | ||
Sony Snc-eb602r Firmware | =1.87.00 | |
Sony Snc-eb602r | ||
Sony Snc-eb632r Firmware | =1.87.00 | |
Sony Snc-eb632r | ||
Sony Snc-em600 Firmware | =1.87.00 | |
Sony Snc-em600 | ||
Sony Snc-em601 Firmware | =1.87.00 | |
Sony Snc-em601 | ||
Sony Snc-em630 Firmware | =1.87.00 | |
Sony Snc-em630 | ||
Sony Snc-em631 Firmware | =1.87.00 | |
Sony Snc-em631 | ||
Sony Snc-em602r Firmware | =1.87.00 | |
Sony Snc-em602r | ||
Sony Snc-em632r Firmware | =1.87.00 | |
Sony Snc-em632r | ||
Sony Snc-em602rc Firmware | =1.87.00 | |
Sony Snc-em602rc | ||
Sony Snc-em632rc Firmware | =1.87.00 | |
Sony Snc-em632rc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3937 is a command injection vulnerability in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00.
CVE-2018-3937 allows an attacker to execute arbitrary commands by sending a specially crafted GET request.
CVE-2018-3937 has a severity rating of 7.2 (out of 10).
Sony IPELA E Series Network Camera G5 firmware 1.87.00 is affected by CVE-2018-3937.
Yes, Sony Snc-eb600 with firmware version 1.87.00 is vulnerable to CVE-2018-3937.