First published: Thu Mar 01 2018(Updated: )
A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to execute arbitrary code.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Mps110-1 Firmware | <3.29.67 | |
Schneider-electric Mps110-1 Firmware | ||
Schneider Electric IMPS110-1ER | <3.29.67 | |
Schneider-electric Imps110-1er Firmware | ||
Schneider-electric Ibps110-1er Firmware | <3.29.67 | |
Schneider-electric Ibps110-1er Firmware | ||
Schneider Electric IMP1110-1E | <3.29.67 | |
Schneider Electric IMP1110-1 | ||
Schneider Electric IMP1110-1E | <3.29.67 | |
Schneider Electric IMP1110-1E | ||
Schneider Electric IMP1110-1 | <3.29.67 | |
Schneider Electric IMP1110-1 | ||
Schneider Electric IBP1110-1ER | <3.29.67 | |
Schneider-electric Ibp1110-1er Firmware | ||
Schneider-electric Imp219-1 Firmware | <3.29.67 | |
Schneider-electric Imp219-1e Firmware | ||
Schneider-electric Imp219-1e | <3.29.67 | |
Schneider-electric Imp219-1e Firmware | ||
Schneider-electric Imp219-1er Firmware | <3.29.67 | |
Schneider-electric Imp219-1 | ||
Schneider-electric Ibp219-1er | <3.29.67 | |
Schneider-electric Ibp219-1er Firmware | ||
Schneider Electric Imp319-1er | <3.29.67 | |
Schneider-electric Imp319-1 Firmware | ||
Schneider-electric Imp319-1e Firmware | <3.29.67 | |
Schneider-electric Imp319-1e Firmware | ||
Schneider-electric IBP319-1ER | <3.29.67 | |
Schneider-electric IBP319-1ER | ||
Schneider Electric IMP519-1 | <3.29.67 | |
Schneider-electric Imp519-1 Firmware | ||
Schneider Electric Imp319-1er | <3.29.67 | |
Schneider Electric Imp319-1er | ||
Schneider-electric Imp519-1e Firmware | <3.29.67 | |
Schneider-electric Imp519-1e Firmware | ||
Schneider-electric Imp519-1er Firmware | <3.29.67 | |
Schneider-electric Imp519-1er Firmware | ||
Schneider Electric IBP519-1ER | <3.29.67 | |
Schneider Electric IBP519-1ER | ||
Schneider-electric Imps110-1e | <3.29.67 | |
Schneider-electric Imps110-1e Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7238 is classified as a critical severity vulnerability due to the potential for remote code execution.
To mitigate CVE-2018-7238, upgrade to firmware version 3.29.67 or later for affected Schneider Electric devices.
CVE-2018-7238 affects Schneider Electric's Pelco Sarix Professional devices running firmware versions prior to 3.29.67.
Yes, CVE-2018-7238 can be exploited by an unauthenticated remote attacker.
CVE-2018-7238 is a buffer overflow vulnerability in the web-based GUI of certain Schneider Electric products.