Record summary

CVE-2017-9965 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.

Description

An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListVersions 2.0 and prioraffected

Nuclei templates

1
ProjectDiscoveryMEDIUMSchneider Electric Pelco VideoXpert Enterprise 2.0 - Path TraversalCVSS 5.8

Schneider Electric Pelco VideoXpert Enterprise versions 2.0 and prior contain a directory traversal caused by insufficient input validation, letting unauthorized persons view web server files, exploit requires no authentication.

Impact

Unauthenticated attackers can view web server files and directories, potentially exposing sensitive configuration files, credentials, and system information.

Remediation

Apply security updates provided by Schneider Electric or upgrade to a non-vulnerable version.

WeaknessesCWE-22
Authors0x_akoko
Template tagscvecve2017schneiderpelcopacketstormlfivideoxpertvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CPE: cpe:2.3:a:schneider-electric:pelco_videoxpert:*:*:*:*:enterprise:*:*:*
Shodan: title:"VideoXpert"

Source: ProjectDiscovery

References

4