ZeroHour

CVE-2018-3938

CVSS 3.0
10.0 critical
EPSS
3%p88
Published
()
Modified
Description

An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST request to trigger this vulnerability.

Vendors
sony
Products
snc-eb600 firmware, snc-eb630 firmware, snc-eb600b firmware, snc-eb630b firmware, snc-eb602r firmware, snc-eb632r firmware, snc-em600 firmware, snc-em601 firmware, snc-em630 firmware, snc-em631 firmware, snc-em602r firmware, snc-em632r firmware
Weakness
CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news