CVE-2018-3938

A

n exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST request to trigger this vulnerability.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sony:snc-eb600_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb600:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sony:snc-eb630_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb630:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sony:snc-eb600b_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb600b:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sony:snc-eb630b_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb630b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sony:snc-eb602r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb602r:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sony:snc-eb632r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-eb632r:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sony:snc-em600_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em600:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:sony:snc-em601_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em601:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:sony:snc-em630_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em630:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:sony:snc-em631_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em631:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:sony:snc-em602r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em602r:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:sony:snc-em632r_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em632r:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:sony:snc-em602rc_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em602rc:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:sony:snc-em632rc_firmware:1.87.00:*:*:*:*:*:*:*
cpe:2.3:h:sony:snc-em632rc:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:06

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 10.0
v2 : 7.5
v3 : 9.1
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0605 - Third Party Advisory () https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0605 - Third Party Advisory