Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.80% | — | Schneider-electric Imps110-1 FirmwareSchneider-electric Imps110-1e FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er Firmware+16 | 3/7/2018 | 17/6/2026 | In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, authenticated users can view passwords in clear text. | |
| Modificada | Alta (8.8) | 0.59% | — | Schneider-electric Imps110-1 FirmwareSchneider-electric Imps110-1e FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er Firmware+16 | 3/7/2018 | 17/6/2026 | In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation. | |
| Modificada | Crítica (9.8) | 1.2% | — | Schneider-electric Imps110-1 FirmwareSchneider-electric Imps110-1e FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er Firmware+16 | 3/7/2018 | 17/6/2026 | In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set". | |
| Modificada | Crítica (9.8) | 2.8% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A buffer overflow vulnerability exist in the web-based GUI of Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to execute arbitrary code. | |
| Modificada | Crítica (9.1) | 1.7% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of 'system.delete.sd_file' | |
| Modificada | Alta (8.1) | 1.3% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could enable SSH service due to lack of authentication for /login/bin/set_param could enable SSH service. | |
| Modificada | Alta (7.5) | 1.6% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of the shell meta characters with the value of 'system.download.sd_file' | |
| Modificada | Alta (7.5) | 0.96% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow arbitrary system file download due to lack of validation of SSL certificate. | |
| Modificada | Crítica (9.8) | 2.0% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'model_name' or 'mac_address'. | |
| Modificada | Crítica (9.8) | 2.0% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'network.ieee8021x.delete_certs'. | |
| Modificada | Crítica (9.8) | 2.0% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow execution of commands due to lack of validation of the shell meta characters with the value of 'system.opkg.remove'. | |
| Modificada | Alta (8.8) | 1.6% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67. | |
| Modificada | Crítica (9.8) | 2.2% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and gain administrator privileges because the use of hardcoded credentials. | |
| Modificada | Crítica (9.8) | 2.2% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow an unauthenticated, remote attacker to bypass authentication and get the administrator privileges. | |
| Modificada | Media (5.3) | 1.2% | — | Schneider-electric Mps110-1 FirmwareSchneider-electric Imps110-1er FirmwareSchneider-electric Ibps110-1er FirmwareSchneider-electric Imp1110-1 Firmware+16 | 9/3/2018 | 17/6/2026 | A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow retrieving of specially crafted URLs without authentication that can reveal sensitive information to an attacker. |