CVE-2018-7230: Schneider Electric IBP1110-1er Firmware

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professional in all firmware versions prior to 3.29.67.

Affected products

Published 2018-03-09. Last modified 2026-06-17.