A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file'
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: schneider

Published: 2018-03-01T00:00:00

Updated: 2018-03-09T22:57:01

Reserved: 2018-02-19T00:00:00


Link: CVE-2018-7237

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-03-09T23:29:00.873

Modified: 2022-02-02T02:08:28.190


Link: CVE-2018-7237

JSON object: View

cve-icon Redhat Information

No data.

CWE