CVE-2018-7798: High severity Schneider-electric Somachine Basic vulnerability
Published Nov 2, 2018
·Updated
A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.
Affected Software
4 affected components
Schneider-electric Somachine Basic
Schneider-electric Modicon M221
All of the following
Schneider-electric Somachine Basic
Schneider-electric Modicon M221
Event History
Nov 2, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-7798.
2
What is the severity rating of CVE-2018-7798?
CVE-2018-7798 has a severity rating of 8.2 (high).
3
What software is affected by CVE-2018-7798?
The Schneider-electric Somachine Basic and Modicon M221 software are affected by CVE-2018-7798.
4
How can CVE-2018-7798 be exploited?
CVE-2018-7798 can be exploited by remotely connecting to the Modicon M221 device and causing a change of IPv4 configuration.
5
Are there any known fixes for CVE-2018-7798?
Yes, refer to the Schneider Electric security advisory SEVD-2018-270-01 for information about fixes or mitigations for CVE-2018-7798.