ID

VAR-201812-0850


CVE

CVE-2018-7832


TITLE

Pro-Face GP-Pro EX Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-013855

DESCRIPTION

An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executable when GP-Pro EX is launched. Pro-Face GP-Pro EX Contains an input validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric Pro-face GP-Pro EX is prone to an arbitrary code-execution vulnerability. A remote attacker can leverage this issue to execute arbitrary code in the context of the affected application. Pro-face GP-Pro EX 4.08 and prior versions are vulnerable

Trust: 1.89

sources: NVD: CVE-2018-7832 // JVNDB: JVNDB-2018-013855 // BID: 106441

AFFECTED PRODUCTS

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.08

Trust: 1.1

vendor:schneider electricmodel:pro-face gp-pro exscope:lteversion:4.08

Trust: 1.0

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.07

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.06

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.05

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.04

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.03

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.02

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.01

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:eqversion:4.00

Trust: 0.3

vendor:schneider electricmodel:pro-face gp-pro exscope:neversion:4.8.200

Trust: 0.3

sources: BID: 106441 // JVNDB: JVNDB-2018-013855 // NVD: CVE-2018-7832

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2018-7832
value: HIGH

Trust: 1.8

CNNVD: CNNVD-201812-1094
value: HIGH

Trust: 0.6

NVD: CVE-2018-7832
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2018-7832
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 1.8

sources: JVNDB: JVNDB-2018-013855 // CNNVD: CNNVD-201812-1094 // NVD: CVE-2018-7832

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2018-013855 // NVD: CVE-2018-7832

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201812-1094

TYPE

Input Validation Error

Trust: 0.9

sources: BID: 106441 // CNNVD: CNNVD-201812-1094

CONFIGURATIONS

sources: NVD: CVE-2018-7832

PATCH

title:SEVD-2018-354-02url:https://www.schneider-electric.com/en/download/document/sevd-2018-354-02/

Trust: 0.8

title:Schneider Electric Pro-Face GP-Pro EX Enter the fix for the verification vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=88167

Trust: 0.6

sources: JVNDB: JVNDB-2018-013855 // CNNVD: CNNVD-201812-1094

EXTERNAL IDS

db:ICS CERTid:ICSA-19-003-01

Trust: 2.7

db:NVDid:CVE-2018-7832

Trust: 2.7

db:BIDid:106441

Trust: 1.9

db:SCHNEIDERid:SEVD-2018-354-02

Trust: 1.6

db:JVNDBid:JVNDB-2018-013855

Trust: 0.8

db:CNNVDid:CNNVD-201812-1094

Trust: 0.6

sources: BID: 106441 // JVNDB: JVNDB-2018-013855 // CNNVD: CNNVD-201812-1094 // NVD: CVE-2018-7832

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-19-003-01

Trust: 2.7

url:http://www.securityfocus.com/bid/106441

Trust: 1.6

url:https://www.schneider-electric.com/en/download/document/sevd-2018-354-02/

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7832

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7832

Trust: 0.8

url:http://www.schneider-electric.com/site/home/index.cfm/ww/?selectcountry=true

Trust: 0.3

url:https://www.proface.com/en/product/soft/gpproex/top

Trust: 0.3

sources: BID: 106441 // JVNDB: JVNDB-2018-013855 // CNNVD: CNNVD-201812-1094 // NVD: CVE-2018-7832

CREDITS

Yu Quiang of Venustech??s ADLab

Trust: 0.3

sources: BID: 106441

SOURCES

db:BIDid:106441
db:JVNDBid:JVNDB-2018-013855
db:CNNVDid:CNNVD-201812-1094
db:NVDid:CVE-2018-7832

LAST UPDATE DATE

2022-05-04T09:28:51.808000+00:00


SOURCES UPDATE DATE

db:BIDid:106441date:2019-01-03T00:00:00
db:JVNDBid:JVNDB-2018-013855date:2019-03-25T00:00:00
db:CNNVDid:CNNVD-201812-1094date:2019-05-29T00:00:00
db:NVDid:CVE-2018-7832date:2019-05-28T18:29:00

SOURCES RELEASE DATE

db:BIDid:106441date:2019-01-03T00:00:00
db:JVNDBid:JVNDB-2018-013855date:2019-03-04T00:00:00
db:CNNVDid:CNNVD-201812-1094date:2018-12-25T00:00:00
db:NVDid:CVE-2018-7832date:2018-12-24T16:29:00