ID

VAR-201807-1856


CVE

CVE-2018-7783


TITLE

Schneider Electric SoMachine Basic  In  XML  External entity vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2018-007904

DESCRIPTION

Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data on the affected node via out-of-band (OOB) attack. The vulnerability is triggered when input passed to the xml parser is not sanitized while parsing the xml project/template file. Schneider Electric SoMachine Basic Has XML An external entity vulnerability exists.Information may be obtained

Trust: 1.71

sources: NVD: CVE-2018-7783 // JVNDB: JVNDB-2018-007904 // VULMON: CVE-2018-7783

AFFECTED PRODUCTS

vendor:schneider electricmodel:somachine basicscope:lteversion:1.6

Trust: 1.0

vendor:schneider electricmodel:somachine basicscope:eqversion: -

Trust: 0.8

vendor:schneider electricmodel:somachine basicscope:ltversion:1.6 sp1 less than

Trust: 0.8

vendor:schneider electricmodel:somachine basicscope:eqversion:1.6

Trust: 0.6

sources: JVNDB: JVNDB-2018-007904 // CNNVD: CNNVD-201807-143 // NVD: CVE-2018-7783

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2018-7783
value: HIGH

Trust: 1.8

CNNVD: CNNVD-201807-143
value: HIGH

Trust: 0.6

VULMON: CVE-2018-7783
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-7783
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

NVD: CVE-2018-7783
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 1.8

sources: VULMON: CVE-2018-7783 // JVNDB: JVNDB-2018-007904 // CNNVD: CNNVD-201807-143 // NVD: CVE-2018-7783

PROBLEMTYPE DATA

problemtype:CWE-611

Trust: 1.0

problemtype:XML Improper restrictions on external entity references (CWE-611) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2018-007904 // NVD: CVE-2018-7783

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201807-143

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-201807-143

CONFIGURATIONS

sources: NVD: CVE-2018-7783

PATCH

title:SEVD-2018-142-01url:https://download.schneider-electric.com/files?p_endoctype=technical+leaflet&p_file_name=sevd-2018-142-01-+somachine+basic.pdf&p_doc_ref=sevd-2018-142-01

Trust: 0.8

title:Schneider Electric SoMachine Basic Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=81712

Trust: 0.6

title:Threatposturl:https://threatpost.com/schneider-electric-patches-xxe-vulnerability-in-plcs/132220/

Trust: 0.1

sources: VULMON: CVE-2018-7783 // JVNDB: JVNDB-2018-007904 // CNNVD: CNNVD-201807-143

EXTERNAL IDS

db:NVDid:CVE-2018-7783

Trust: 2.5

db:SCHNEIDERid:SEVD-2018-142-01

Trust: 1.7

db:JVNid:JVNVU92527693

Trust: 0.8

db:JVNDBid:JVNDB-2018-007904

Trust: 0.8

db:ICS CERTid:ICSA-21-103-01

Trust: 0.6

db:AUSCERTid:ESB-2021.1249

Trust: 0.6

db:CNNVDid:CNNVD-201807-143

Trust: 0.6

db:VULMONid:CVE-2018-7783

Trust: 0.1

sources: VULMON: CVE-2018-7783 // JVNDB: JVNDB-2018-007904 // CNNVD: CNNVD-201807-143 // NVD: CVE-2018-7783

REFERENCES

url:https://www.schneider-electric.com/en/download/document/sevd-2018-142-01/

Trust: 1.7

url:https://jvn.jp/vu/jvnvu92527693/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7783

Trust: 0.8

url:https://us-cert.cisa.gov/ics/advisories/icsa-21-103-01

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.1249

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/611.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://threatpost.com/schneider-electric-patches-xxe-vulnerability-in-plcs/132220/

Trust: 0.1

sources: VULMON: CVE-2018-7783 // JVNDB: JVNDB-2018-007904 // CNNVD: CNNVD-201807-143 // NVD: CVE-2018-7783

SOURCES

db:VULMONid:CVE-2018-7783
db:JVNDBid:JVNDB-2018-007904
db:CNNVDid:CNNVD-201807-143
db:NVDid:CVE-2018-7783

LAST UPDATE DATE

2022-05-04T10:00:39.404000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2018-7783date:2018-09-08T00:00:00
db:JVNDBid:JVNDB-2018-007904date:2021-04-15T07:02:00
db:CNNVDid:CNNVD-201807-143date:2021-08-24T00:00:00
db:NVDid:CVE-2018-7783date:2022-01-31T19:43:00

SOURCES RELEASE DATE

db:VULMONid:CVE-2018-7783date:2018-07-03T00:00:00
db:JVNDBid:JVNDB-2018-007904date:2018-10-01T00:00:00
db:CNNVDid:CNNVD-201807-143date:2018-07-04T00:00:00
db:NVDid:CVE-2018-7783date:2018-07-03T14:29:00