CVE-2018-7822: Medium severity schneider electric somachine basic vulnerability
An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting SoMachine Basic.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-7822.
What is the severity of CVE-2018-7822?
CVE-2018-7822 has a severity rating of 5.5, which is considered medium.
Which software versions are affected by CVE-2018-7822?
SoMachine Basic all versions and Modicon M221 firmware versions prior to V1.10.0.0 are affected by CVE-2018-7822.
How can unauthorized access to SoMachine Basic resource files be caused?
Unauthorized access to SoMachine Basic resource files can be caused by exploiting the Incorrect Default Permissions vulnerability.
Where can I find more information about CVE-2018-7822?
You can find more information about CVE-2018-7822 at the following link: [https://www.schneider-electric.com/en/download/document/SEVD-2019-045-01/](https://www.schneider-electric.com/en/download/document/SEVD-2019-045-01/)