First published: Thu Mar 01 2018(Updated: )
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator privileges because the use of hardcoded credentials.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Mps110-1 Firmware | <3.29.67 | |
Schneider-electric Mps110-1 Firmware | ||
IMPS110-1ER Firmware | <3.29.67 | |
Schneider-electric Imps110-1er Firmware | ||
Schneider-electric Ibps110-1er Firmware | <3.29.67 | |
Schneider-electric Ibps110-1er Firmware | ||
Schneider Electric IMP1110-1E | <3.29.67 | |
Schneider Electric IMP1110-1 | ||
Schneider Electric IMP1110-1E | <3.29.67 | |
Schneider Electric IMP1110-1E | ||
Schneider Electric IMP1110-1 | <3.29.67 | |
Schneider Electric IMP1110-1 | ||
Schneider Electric IBP1110-1ER | <3.29.67 | |
Schneider-electric Ibp1110-1er Firmware | ||
Schneider Electric IMP219-1E | <3.29.67 | |
Schneider Electric Imp219-1 | ||
Schneider Electric Imp219-1e Firmware | <3.29.67 | |
Schneider Electric IMP219-1E | ||
Schneider Electric Imp219-1er Firmware | <3.29.67 | |
Schneider-electric Imp219-1 | ||
Schneider Electric IBP219-1ER Firmware | <3.29.67 | |
Schneider Electric IBP219-1ER | ||
Schneider Electric IMP319-1E Firmware | <3.29.67 | |
Schneider-electric Imp319-1 Firmware | ||
Schneider Electric IMP319-1E Firmware | <3.29.67 | |
Schneider-electric Imp319-1e Firmware | ||
Schneider-electric IBP319-1ER | <3.29.67 | |
Schneider Electric IBP319-1ER | ||
Schneider Electric IMP519-1 Firmware | <3.29.67 | |
Schneider-electric Imp519-1 Firmware | ||
Schneider Electric Imp319-1er | <3.29.67 | |
Schneider Electric Imp319-1er | ||
Schneider Electric IMP519-1 Firmware | <3.29.67 | |
Schneider-electric Imp519-1e Firmware | ||
Schneider Electric IMP519-1 Firmware | <3.29.67 | |
Schneider-electric Imp519-1er Firmware | ||
Schneider Electric IBP519-1ER | <3.29.67 | |
Schneider Electric IBP519-1ER | ||
Schneider Electric IMPS110-1E | <3.29.67 | |
Schneider Electric IMPS110-1E |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7229 is considered a critical vulnerability due to its potential for unauthenticated remote access and system compromise.
To remediate CVE-2018-7229, upgrade the firmware to version 3.29.67 or later for all affected Schneider Electric devices.
CVE-2018-7229 affects all firmware versions prior to 3.29.67 for Schneider Electric's Pelco Sarix Professional devices.
CVE-2018-7229 can be exploited by an unauthenticated remote attacker to bypass authentication and gain administrator privileges.
Yes, the use of hardcoded credentials in Schneider Electric devices is the primary cause of CVE-2018-7229.