9

CVE-2018-7829

An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which allows an attacker to execute arbitrary system commands.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electricD6220 Firmware Version >= 2.11
   Schneider-electricD6220 Version-
Schneider-electricD6220l Firmware Version >= 2.11
   Schneider-electricD6220l Version-
Schneider-electricD6230 Firmware Version >= 2.11
   Schneider-electricD6230 Version-
Schneider-electricD6230l Firmware Version >= 2.11
   Schneider-electricD6230l Version-
Schneider-electricImes19-1i Firmware Version < 2.2.3.0
   Schneider-electricImes19-1i Version-
Schneider-electricImes19-1s Firmware Version < 2.2.3.0
   Schneider-electricImes19-1s Version-
Schneider-electricImes19-1p Firmware Version < 2.2.3.0
   Schneider-electricImes19-1p Version-
Schneider-electricIme119-1i Firmware Version < 2.2.3.0
   Schneider-electricIme119-1i Version-
Schneider-electricIme119-1s Firmware Version < 2.2.3.0
   Schneider-electricIme119-1s Version-
Schneider-electricIme119-1p Firmware Version < 2.2.3.0
   Schneider-electricIme119-1p Version-
Schneider-electricIme219-1i Firmware Version < 2.2.3.0
   Schneider-electricIme219-1i Version-
Schneider-electricIme219-1s Firmware Version < 2.2.3.0
   Schneider-electricIme219-1s Version-
Schneider-electricIme219-1p Firmware Version < 2.2.3.0
   Schneider-electricIme219-1p Version-
Schneider-electricIme319-1i Firmware Version < 2.2.3.0
   Schneider-electricIme319-1i Version-
Schneider-electricIme319-1s Firmware Version < 2.2.3.0
   Schneider-electricIme319-1s Version-
Schneider-electricIme319-1p Firmware Version < 2.2.3.0
   Schneider-electricIme319-1p Version-
Schneider-electricIme319-b1i Firmware Version < 2.2.3.0
   Schneider-electricIme319-b1i Version-
Schneider-electricIme319-b1s Firmware Version < 2.2.3.0
   Schneider-electricIme319-b1s Version-
Schneider-electricIme319-b1p Firmware Version < 2.2.3.0
   Schneider-electricIme319-b1p Version-
Schneider-electricIme3122-1i Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1i Version-
Schneider-electricIme3122-b1i Firmware Version < 2.2.3.0
   Schneider-electricIme3122-b1i Version-
Schneider-electricIme3122-1s Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1s Version-
Schneider-electricIme3122-b1s Firmware Version < 2.2.3.0
   Schneider-electricIme3122-b1s Version-
Schneider-electricIme3122-1p Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1p Version-
Schneider-electricIme3122-b1p Firmware Version < 2.2.3.0
   Schneider-electricIme3122-b1p Version-
Schneider-electricImes19-1ei Firmware Version < 2.2.3.0
   Schneider-electricImes19-1ei Version-
Schneider-electricImes19-1es Firmware Version < 2.2.3.0
   Schneider-electricImes19-1es Version-
Schneider-electricImes19-1ep Firmware Version < 2.2.3.0
   Schneider-electricImes19-1ep Version-
Schneider-electricIme119-1ei Firmware Version < 2.2.3.0
   Schneider-electricIme119-1ei Version-
Schneider-electricIme119-1es Firmware Version < 2.2.3.0
   Schneider-electricIme119-1es Version-
Schneider-electricIme119-1ep Firmware Version < 2.2.3.0
   Schneider-electricIme119-1ep Version-
Schneider-electricIme219-1ei Firmware Version < 2.2.3.0
   Schneider-electricIme219-1ei Version-
Schneider-electricIme219-1es Firmware Version < 2.2.3.0
   Schneider-electricIme219-1es Version-
Schneider-electricIme219-1ep Firmware Version < 2.2.3.0
   Schneider-electricIme219-1ep Version-
Schneider-electricIme319-1ei Firmware Version < 2.2.3.0
   Schneider-electricIme319-1ei Version-
Schneider-electricIme319-1es Firmware Version < 2.2.3.0
   Schneider-electricIme319-1es Version-
Schneider-electricIme319-1ep Firmware Version < 2.2.3.0
   Schneider-electricIme319-1ep Version-
Schneider-electricIme3122-1ei Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1ei Version-
Schneider-electricIme3122-1es Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1es Version-
Schneider-electricIme3122-1ep Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1ep Version-
Schneider-electricImes19-1vi Firmware Version < 2.2.3.0
   Schneider-electricImes19-1vi Version-
Schneider-electricImes19-1vs Firmware Version < 2.2.3.0
   Schneider-electricImes19-1vs Version-
Schneider-electricImes19-1vp Firmware Version < 2.2.3.0
   Schneider-electricImes19-1vp Version-
Schneider-electricIme119-1vi Firmware Version < 2.2.3.0
   Schneider-electricIme119-1vi Version-
Schneider-electricIme119-1vs Firmware Version < 2.2.3.0
   Schneider-electricIme119-1vs Version-
Schneider-electricIme119-1vp Firmware Version < 2.2.3.0
   Schneider-electricIme119-1vp Version-
Schneider-electricIme219-1vi Firmware Version < 2.2.3.0
   Schneider-electricIme219-1vi Version-
Schneider-electricIme219-1vs Firmware Version < 2.2.3.0
   Schneider-electricIme219-1vs Version-
Schneider-electricIme219-1vp Firmware Version < 2.2.3.0
   Schneider-electricIme219-1vp Version-
Schneider-electricIme319-1vi Firmware Version < 2.2.3.0
   Schneider-electricIme319-1vi Version-
Schneider-electricIme319-1vs Firmware Version < 2.2.3.0
   Schneider-electricIme319-1vs Version-
Schneider-electricIme319-1vp Firmware Version < 2.2.3.0
   Schneider-electricIme319-1vp Version-
Schneider-electricIme3122-1vi Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1vi Version-
Schneider-electricIme3122-1vs Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1vs Version-
Schneider-electricIme3122-1vp Firmware Version < 2.2.3.0
   Schneider-electricIme3122-1vp Version-
Schneider-electricIxes1 Firmware Version < 2.2.3.0
   Schneider-electricIxes1 Version-
Schneider-electricIxe11 Firmware Version < 2.2.3.0
   Schneider-electricIxe11 Version-
Schneider-electricIxe21 Firmware Version < 2.2.3.0
   Schneider-electricIxe21 Version-
Schneider-electricIxe31 Firmware Version < 2.2.3.0
   Schneider-electricIxe31 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.66
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-943 Improper Neutralization of Special Elements in Data Query Logic

The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.