XML External Entity Vulnerability in Schneider Electric SoMachine Basic Software
CVE-2018-7783

7.5HIGH

Key Information:

Vendor
CVE Published:
3 July 2018

Summary

The SoMachine Basic software from Schneider Electric is affected by an XML External Entity (XXE) vulnerability, which can be exploited by attackers through the DTD parameter entities technique. This can lead to the disclosure and retrieval of sensitive data from the affected node via out-of-band (OOB) attacks. The vulnerability arises from a lack of proper input sanitization when the XML parser processes project or template files, allowing attackers to manipulate XML data and execute unauthorized actions.

Affected Version(s)

SoMachine Basic SoMachine Basic prior to v1.6 SP1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.