vendor:
Pelco Endura NET55XX Encoder
by:
Lucas Dinucci, Vitor Esperança
9.8
CVSS
CRITICAL
Inadequate Access Controls
CWE
Product Name: Pelco Endura NET55XX Encoder
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2019-6814
CPE:
Platforms Tested: Unix
2019
Schneider Electric Pelco Endura NET55XX Encoder
This module exploits inadequate access controls within the webUI to enable the SSH service and change the root password. It has been tested successfully on various versions of the NET55XX Encoder.
Mitigation:
Apply the necessary patches and ensure proper access controls are in place.