CVE-2018-7781: High severity Schneider-electric Imps110-1 Firmware vulnerability
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric Pelco Sarix Professional 1st generation camerasto a version that resolves this vulnerability.Fixed in 3.29.69 - Compensating control
Since the issue affects cameras with firmware prior to 3.29.69 and can be triggered by an authenticated user with a specially crafted request, restrict authenticated access to the camera web interface/API (e.g., limit who can log in and reach the service) until the firmware is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7781?
CVE-2018-7781 is rated as a critical vulnerability, as it allows an authenticated user to view passwords in clear text, leading to potential privilege escalation.
How do I fix CVE-2018-7781?
To mitigate CVE-2018-7781, upgrade the firmware of the affected Schneider Electric Pelco Sarix Professional cameras to version 3.29.69 or later.
What types of devices are affected by CVE-2018-7781?
CVE-2018-7781 affects Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69.
What is the impact of exploiting CVE-2018-7781?
Exploitation of CVE-2018-7781 can result in unauthorized access to sensitive information, including passwords, and lead to privilege escalation.
How can I check if my device is vulnerable to CVE-2018-7781?
To determine if your device is vulnerable to CVE-2018-7781, verify the firmware version of your Schneider Electric Pelco Sarix Professional cameras against the affected versions.