CVE-2018-3937

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sony:snc-eb600_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb600:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sony:snc-eb630_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb630:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sony:snc-eb600b_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb600b:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sony:snc-eb630b_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb630b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sony:snc-eb602r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb602r:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sony:snc-eb632r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb632r:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sony:snc-em600_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em600:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:sony:snc-em601_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em601:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:sony:snc-em630_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em630:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:sony:snc-em631_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em631:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:sony:snc-em602r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em602r:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:sony:snc-em632r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em632r:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:sony:snc-em602rc_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em602rc:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:sony:snc-em632rc_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em632rc:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:06

Type Values Removed Values Added
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0604 - Exploit, Third Party Advisory () https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0604 - Exploit, Third Party Advisory
CVSS v2 : 6.5
v3 : 7.2
v2 : 6.5
v3 : 9.1

Information

Published : 2018-08-14 19:29

Updated : 2024-11-21 04:06


NVD link : CVE-2018-3937

Mitre link : CVE-2018-3937

CVE.ORG link : CVE-2018-3937


JSON object : View

Products Affected

sony

  • snc-eb600
  • snc-em602rc
  • snc-em632r
  • snc-em632rc
  • snc-eb630b_firmware
  • snc-em600_firmware
  • snc-em601
  • snc-eb600b
  • snc-em601_firmware
  • snc-eb600b_firmware
  • snc-em602rc_firmware
  • snc-em630
  • snc-eb602r_firmware
  • snc-eb630_firmware
  • snc-eb632r
  • snc-eb630
  • snc-eb600_firmware
  • snc-em600
  • snc-em602r
  • snc-em602r_firmware
  • snc-eb602r
  • snc-em632r_firmware
  • snc-em630_firmware
  • snc-em631
  • snc-em632rc_firmware
  • snc-eb632r_firmware
  • snc-em631_firmware
  • snc-eb630b
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')