mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
73 lines
2.4 KiB
JSON
73 lines
2.4 KiB
JSON
{
|
|
"CVE_data_meta": {
|
|
"ASSIGNER": "cybersecurity@schneider-electric.com",
|
|
"DATE_PUBLIC": "2018-02-12T00:00:00",
|
|
"ID": "CVE-2017-9966",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "Pelco VideoXpert Enterprise",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "Versions 2.0 and prior"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"vendor_name": "Schneider Electric SE"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"data_format": "MITRE",
|
|
"data_type": "CVE",
|
|
"data_version": "4.0",
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "Privilege Escalation"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"name": "https://ics-cert.us-cert.gov/advisories/ICSA-17-355-02",
|
|
"refsource": "MISC",
|
|
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-17-355-02"
|
|
},
|
|
{
|
|
"name": "https://www.schneider-electric.com/en/download/document/SEVD-2017-339-01/",
|
|
"refsource": "CONFIRM",
|
|
"url": "https://www.schneider-electric.com/en/download/document/SEVD-2017-339-01/"
|
|
},
|
|
{
|
|
"name": "102338",
|
|
"refsource": "BID",
|
|
"url": "http://www.securityfocus.com/bid/102338"
|
|
}
|
|
]
|
|
}
|
|
} |