CVE-2018-7801: Code Injection
Published Dec 24, 2018
·Updated
A Code Injection vulnerability exists in EVLink Parking, v3.2.0-12v1 and earlier, which could enable access with maximum privileges when a remote code execution is performed.
Affected Software
2 affected components
Schneider-electric Evlink Parking Firmware<=3.2.0-12
Schneider-electric Evlink Parking
Remediation
Event History
Dec 24, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-7801?
CVE-2018-7801 is considered a critical vulnerability due to its potential for remote code execution with maximum privileges.
2
How do I fix CVE-2018-7801?
To fix CVE-2018-7801, upgrade the EVLink Parking firmware to a version later than 3.2.0-12.
3
Who is affected by CVE-2018-7801?
CVE-2018-7801 affects users of Schneider Electric's EVLink Parking firmware version 3.2.0-12 and earlier.
4
What type of vulnerability is CVE-2018-7801?
CVE-2018-7801 is a code injection vulnerability that enables unauthorized remote code execution.
5
Can CVE-2018-7801 be exploited remotely?
Yes, CVE-2018-7801 can be exploited remotely, allowing attackers to gain maximum privileges.