CVE-2018-7841: Schneider Electric U.motion Builder SQL Injection Vulnerability
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
Other sources
A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect Schneider Electric U.motion Builder instances from networks (isolate them) if still in use; the product is end-of-life and vulnerable to a SQL Injection flaw.
- Operational
Inventory your environment for Schneider Electric U.motion Builder and identify any installations running version 1.3.4; ensure those identified instances are immediately disconnected/isolated.
Event History
Frequently Asked Questions
What is CVE-2018-7841?
CVE-2018-7841 is a SQL Injection vulnerability that exists in U.motion Builder software version 1.3.4.
What is the severity of CVE-2018-7841?
CVE-2018-7841 has a severity score of 9.8 (Critical).
What is the impact of CVE-2018-7841?
CVE-2018-7841 could allow an attacker to execute unwanted code by entering an improper set of characters.
How can I fix CVE-2018-7841?
To fix CVE-2018-7841, it is recommended to update U.motion Builder software to version 1.4 or later.
Where can I find more information about CVE-2018-7841?
You can find more information about CVE-2018-7841 in the references provided: [link1], [link2], [link3].