CVE Published: 09/03/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: schneider |
Vendor: Schneider Electric SE |
Product: Pelco Sarix Professional Status : PUBLISHED
CVE-2018-7237 Description
A vulnerability exists in Schneider Electric\'s Pelco Sarix Professional in all firmware versions prior to 3.29.67 which could allow a remote attacker to delete arbitrary system file due to lack of validation of the /login/bin/set_param to the file name with the value of \'system.delete.sd_file\'