In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, by sending a specially crafted request an authenticated user can view password in clear text and results in privilege escalation.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://www.schneider-electric.com/en/download/document/SEVD-2018-114-01/ | vendor advisory |