XML External Entity Vulnerability in Schneider Electric SoMachine Basic Software
CVE-2018-7783
7.5HIGH
Summary
The SoMachine Basic software from Schneider Electric is affected by an XML External Entity (XXE) vulnerability, which can be exploited by attackers through the DTD parameter entities technique. This can lead to the disclosure and retrieval of sensitive data from the affected node via out-of-band (OOB) attacks. The vulnerability arises from a lack of proper input sanitization when the XML parser processes project or template files, allowing attackers to manipulate XML data and execute unauthorized actions.
Affected Version(s)
SoMachine Basic SoMachine Basic prior to v1.6 SP1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved