First published: Fri Mar 09 2018(Updated: )
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Mps110-1 Firmware | <3.29.67 | |
Schneider-electric Mps110-1 Firmware | ||
Schneider Electric IMPS110-1ER | <3.29.67 | |
Schneider-electric Imps110-1er Firmware | ||
Schneider-electric Ibps110-1er Firmware | <3.29.67 | |
Schneider-electric Ibps110-1er Firmware | ||
Schneider Electric IMP1110-1E | <3.29.67 | |
Schneider Electric IMP1110-1 | ||
Schneider Electric IMP1110-1E | <3.29.67 | |
Schneider Electric IMP1110-1E | ||
Schneider Electric IMP1110-1 | <3.29.67 | |
Schneider Electric IMP1110-1 | ||
Schneider Electric IBP1110-1ER | <3.29.67 | |
Schneider-electric Ibp1110-1er Firmware | ||
Schneider-electric Imp219-1 Firmware | <3.29.67 | |
Schneider-electric Imp219-1e Firmware | ||
Schneider-electric Imp219-1e | <3.29.67 | |
Schneider-electric Imp219-1e Firmware | ||
Schneider-electric Imp219-1er Firmware | <3.29.67 | |
Schneider-electric Imp219-1 | ||
Schneider-electric Ibp219-1er | <3.29.67 | |
Schneider-electric Ibp219-1er Firmware | ||
Schneider Electric Imp319-1er | <3.29.67 | |
Schneider-electric Imp319-1 Firmware | ||
Schneider-electric Imp319-1e Firmware | <3.29.67 | |
Schneider-electric Imp319-1e Firmware | ||
Schneider-electric IBP319-1ER | <3.29.67 | |
Schneider-electric IBP319-1ER | ||
Schneider Electric IMP519-1 | <3.29.67 | |
Schneider-electric Imp519-1 Firmware | ||
Schneider Electric Imp319-1er | <3.29.67 | |
Schneider Electric Imp319-1er | ||
Schneider-electric Imp519-1e Firmware | <3.29.67 | |
Schneider-electric Imp519-1e Firmware | ||
Schneider-electric Imp519-1er Firmware | <3.29.67 | |
Schneider-electric Imp519-1er Firmware | ||
Schneider Electric IBP519-1ER | <3.29.67 | |
Schneider Electric IBP519-1ER | ||
Schneider-electric Imps110-1e | <3.29.67 | |
Schneider-electric Imps110-1e Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7228 is classified as a critical vulnerability due to its potential to allow unauthenticated remote access to administrator privileges.
To remediate CVE-2018-7228, update the Schneider Electric Pelco Sarix Professional firmware to version 3.29.67 or later.
CVE-2018-7228 affects various models of Schneider Electric cameras, including the Pelco Sarix Professional series, running firmware versions prior to 3.29.67.
Yes, CVE-2018-7228 can be exploited by unauthenticated remote attackers, making it a serious security concern.
If using an affected version, it is crucial to immediately upgrade to the latest firmware to mitigate security risks associated with CVE-2018-7228.