CVE-2017-9964: Schneider Electric Pelco Videoxpert
Medium severity, CVSS 6.9. EPSS: 2% chance of exploitation in the next 30 days.
A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.
Affected products
- Schneider Electric Pelco Videoxpert: before 2.1 (fixed in 2.1)
Published 2018-01-02. Last modified 2026-06-17.