First published: Tue Aug 14 2018(Updated: )
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sony Snc-eb600 Firmware | =1.87.00 | |
Sony Snc-eb600 | ||
Sony Snc-eb630 Firmware | =1.87.00 | |
Sony Snc-eb630 | ||
Sony Snc-eb600b Firmware | =1.87.00 | |
Sony Snc-eb600b | ||
Sony Snc-eb630b Firmware | =1.87.00 | |
Sony Snc-eb630b | ||
Sony Snc-eb602r Firmware | =1.87.00 | |
Sony Snc-eb602r | ||
Sony Snc-eb632r Firmware | =1.87.00 | |
Sony Snc-eb632r | ||
Sony Snc-em600 Firmware | =1.87.00 | |
Sony Snc-em600 | ||
Sony Snc-em601 Firmware | =1.87.00 | |
Sony Snc-em601 | ||
Sony Snc-em630 Firmware | =1.87.00 | |
Sony Snc-em630 | ||
Sony Snc-em631 Firmware | =1.87.00 | |
Sony Snc-em631 | ||
Sony Snc-em602r Firmware | =1.87.00 | |
Sony Snc-em602r | ||
Sony Snc-em632r Firmware | =1.87.00 | |
Sony Snc-em632r | ||
Sony Snc-em602rc Firmware | =1.87.00 | |
Sony Snc-em602rc | ||
Sony Snc-em632rc Firmware | =1.87.00 | |
Sony Snc-em632rc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3938 is a stack-based buffer overflow vulnerability in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00.
CVE-2018-3938 affects Sony IPELA E Series Camera G5 firmware version 1.87.00.
CVE-2018-3938 has a severity rating of critical.
CVE-2018-3938 can be exploited by sending a specially crafted POST request, causing a stack-based buffer overflow and resulting in remote code execution.
Yes, to fix CVE-2018-3938, users should update their Sony IPELA E Series Camera G5 firmware to version 1.87.01 or later.