Vulnerabilities > Schneider Electric > Imp1110 1 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-07-03 CVE-2018-7782 Insufficiently Protected Credentials vulnerability in Schneider-Electric products
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text.
network
low complexity
schneider-electric CWE-522
4.0
2018-07-03 CVE-2018-7781 Missing Encryption of Sensitive Data vulnerability in Schneider-Electric products
In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.
network
low complexity
schneider-electric CWE-311
4.0
2018-03-09 CVE-2018-7237 Improper Input Validation vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'
network
low complexity
schneider-electric CWE-20
6.4
2018-03-09 CVE-2018-7236 Improper Authentication vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service.
5.8
2018-03-09 CVE-2018-7230 XXE vulnerability in Schneider-Electric products
A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.
6.8
2018-03-09 CVE-2018-7227 Improper Authentication vulnerability in Schneider-Electric products
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker.
network
low complexity
schneider-electric CWE-287
5.0