CVE-2017-9966
Summary
| CVE | CVE-2017-9966 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-02 03:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Schneider-electric | Pelco Videoxpert | All | All | All | All |
| Application | Schneider-electric | Pelco Videoxpert | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Notification - Pelco Video | Download Schneider Electric | CONFIRM | www.schneider-electric.com | |
| Schneider Electric Pelco VideoXpert Enterprise Directory Traversal And Access Bypass Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Schneider Electric Pelco VideoXpert Enterprise | ICS-CERT | MISC | ics-cert.us-cert.gov | Patch, Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590837 Schneider Electric Pelco VideoXpert Enterprise Multiple Vulnerabilities (ICSA-17-355-02)