CVE-2017-9965
Schneider Electric Pelco VideoXpert Enterprise 2.0 - Path Traversal
Record summary
CVE-2017-9965 has a selected CVSS score of 5.8 (medium); EIP currently links 1 Nuclei template.
Description
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Pelco VideoXpert EnterpriseBrowse Schneider Electric SE / Pelco VideoXpert Enterprise | CVE List | Versions 2.0 and prior | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSchneider Electric Pelco VideoXpert Enterprise 2.0 - Path TraversalCVSS 5.8
Schneider Electric Pelco VideoXpert Enterprise versions 2.0 and prior contain a directory traversal caused by insufficient input validation, letting unauthorized persons view web server files, exploit requires no authentication.
Impact
Unauthenticated attackers can view web server files and directories, potentially exposing sensitive configuration files, credentials, and system information.
Remediation
Apply security updates provided by Schneider Electric or upgrade to a non-vulnerable version.
Source: ProjectDiscovery