CVE-2017-9964 is a Path Traversal vulnerability affecting all versions of Schneider Electric Pelco VideoXpert Enterprise prior to 2.1. An attacker can exploit this by sniffing network communications to execute a directory traversal attack. This medium-severity vulnerability (CVSS 6.9) has a network attack vector with high attack complexity, potentially leading to authentication bypass or session hijacking. There is no known active exploitation, public exploit code, or significant community discussion, with only one article covering the patch release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1CPE matchmatch criteria | cpe:2.3:a:schneider-electric:pelco_videoxpert:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.