XML External Entity Vulnerability in Schneider Electric SoMachine Basic Software
CVE-2018-7783
What is CVE-2018-7783?
The SoMachine Basic software from Schneider Electric is affected by an XML External Entity (XXE) vulnerability, which can be exploited by attackers through the DTD parameter entities technique. This can lead to the disclosure and retrieval of sensitive data from the affected node via out-of-band (OOB) attacks. The vulnerability arises from a lack of proper input sanitization when the XML parser processes project or template files, allowing attackers to manipulate XML data and execute unauthorized actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SoMachine Basic SoMachine Basic prior to v1.6 SP1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved