vendor:
Pelco Sarix/Spectra Cameras
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
CSRF
352
CWE
Product Name: Pelco Sarix/Spectra Cameras
Affected Version From: Sarix Enhanced - Model: IME219 (Firmware: 2.1.2.0.8280-A0.0)
Affected Version To: Spectra Enhanced - Model: D6230 (Firmware: 2.2.0.5.9340-A0.0)
Patch Exists: YES
Related CWE: N/A
CPE: h:schneider_electric:pelco_sarix_spectra_cameras
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6.10_mvl401-1721-pelco_evolution, MontaVista(R) Linux(R) Professional Edition 4.0.1 (0600980), Lighttpd/1.4.28, PHP/5.3.0
2017
Schneider Electric Pelco Sarix/Spectra Cameras CSRF Enable SSH Root Access
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Implement proper input validation and authentication checks to verify the requests.