Incorrect Default Permissions Vulnerability in SoMachine Basic by Schneider Electric
CVE-2018-7822
5.5MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 22 May 2019
Summary
An incorrect default permissions vulnerability exists in SoMachine Basic and Modicon M221, allowing unauthorized access to sensitive resource files on systems utilizing SoMachine Basic. This issue may expose crucial configuration and operational data, creating potential security risks for users who do not update their systems or apply the appropriate security measures.
Affected Version(s)
SoMachine Basic and Modicon M221, SoMachine Basic, all Modicon M221, all references, all prior to firmware V1.10.0.0 SoMachine Basic and Modicon M221, SoMachine Basic, all versions Modicon M221, all references, all versions prior to firmware V1.10.0.0
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved