ZeroHour

CVE-2018-3937

PoC
CVSS 3.0
7.2 high
EPSS
10%p95
Published
()
Modified
Description

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.

Vendors
sony
Products
snc-eb600 firmware, snc-eb630 firmware, snc-eb600b firmware, snc-eb630b firmware, snc-eb602r firmware, snc-eb632r firmware, snc-em600 firmware, snc-em601 firmware, snc-em630 firmware, snc-em631 firmware, snc-em602r firmware, snc-em632r firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news