{
    "id": "CVE-2016-4520",
    "published": "2016-07-15 16:59:09",
    "last_modified": "2026-06-17 00:47:42",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.0",
    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": null,
    "description": "Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, which allows remote attackers to obtain access, and consequently execute arbitrary code, via unspecified vectors.",
    "epss_score": "0.05790",
    "epss_percentile": "0.92901",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-06 18:17:14",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "schneider-electric",
            "product": "pelco_digital_sentry_video_management_system_firmware"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "http://www.schneider-electric.com/ww/en/download/document/SEVD-2016-153-01",
        "http://www.securityfocus.com/bid/91783",
        "https://ics-cert.us-cert.gov/advisories/ICSA-16-196-01",
        "http://www.schneider-electric.com/ww/en/download/document/SEVD-2016-153-01",
        "http://www.securityfocus.com/bid/91783",
        "https://ics-cert.us-cert.gov/advisories/ICSA-16-196-01"
    ]
}