CVE Vulnerabilities

CVE-2018-7234

Improper Certificate Validation

Published: Mar 09, 2018 | Modified: Feb 02, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in Schneider Electrics Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Mps110-1_firmware Schneider-electric * 3.29.67 (excluding)

Potential Mitigations

References