Security Advisory

CVE-2018-3937

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-08-14 19:00:00
Last updated 2024-09-16 16:13:19
Assigner talos
State PUBLISHED

Description

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.